CVE-2020-9399: Medium severity Avast Antivirus for Linux vulnerability
The Avast AV parsing engine allows virus-detection bypass via a crafted ZIP archive. This affects versions before 12 definitions 200114-0 of Antivirus Pro, Antivirus Pro Plus, and Antivirus for Linux.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Avast Antivirus Pro / Antivirus Pro Plus / Antivirus for Linux (Avast AV parsing engine)to a version that resolves this vulnerability.Fixed in 12 definitions 200114-0
Event History
Frequently Asked Questions
What is CVE-2020-9399?
CVE-2020-9399 is a vulnerability that allows virus-detection bypass in Avast antivirus products.
Which Avast products are affected by CVE-2020-9399?
Avast Antivirus Pro, Avast Antivirus Pro Plus, and Avast Antivirus For Linux versions before 12 definitions 200114-0 are affected.
How severe is CVE-2020-9399?
CVE-2020-9399 has a severity rating of medium.
How can I fix CVE-2020-9399?
Upgrade Avast Antivirus Pro, Avast Antivirus Pro Plus, and Avast Antivirus For Linux to version 12 definitions 200114-0 or later.
What is the Common Weakness Enumeration (CWE) ID of CVE-2020-9399?
The CWE ID of CVE-2020-9399 is 436.