CVE-2024-9483: Uninitialized variable in digital signiture verification may crash the application
Published Oct 4, 2024
·Updated
A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash the application during processing.
Affected Software
2 affected components
Avast Antivirus Macos<24092400
AVG Antivirus Macos<24092400
Remediation
Information
Upgrade to the latest version of virus definitions.
Event History
Oct 4, 2024
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-9483?
CVE-2024-9483 is classified as a critical vulnerability due to the potential for application crashes.
2
How do I fix CVE-2024-9483?
To fix CVE-2024-9483, update Avast or AVG Antivirus to the latest version beyond 24092400.
3
Which versions of AVG and Avast are affected by CVE-2024-9483?
CVE-2024-9483 affects AVG and Avast Antivirus versions prior to 24092400 on MacOS.
4
What impact does CVE-2024-9483 have on users?
CVE-2024-9483 can cause the antivirus application to crash when processing malformed xar files.
5
Is CVE-2024-9483 remotely exploitable?
CVE-2024-9483 requires user interaction, as it involves processing a specifically crafted xar file.