{ "id": "CVE-2010-0705", "sourceIdentifier": "cve@mitre.org", "published": "2010-02-25T18:30:00.377", "lastModified": "2018-10-10T19:53:24.980", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption." }, { "lang": "es", "value": "Aavmker4.sys en avast! desde v4.8 hasta v4.8.1368.0 y v5.0 anteriores a v5.0.418.0 corriendo sobre Windows 2000 o XP, no valida adecuadamente una entrada a IOCTL 0xb2d60030, lo que permite a usuarios locales producir una denegaci\u00f3n de servicio (ca\u00edda del sistema) o ejecutar c\u00f3digo arbitrario para ganar privilegios a trav\u00e9s de peticiones IOCTL utilizando direcciones de kernel manipuladas que inician una corrupci\u00f3n de memoria." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C", "accessVector": "LOCAL", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE", "baseScore": 7.2 }, "baseSeverity": "HIGH", "exploitabilityScore": 3.9, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-20" } ] } ], "configurations": [ { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_home:*:*:windows:*:*:*:*:*", "versionEndIncluding": "5.0.396.0", "matchCriteriaId": "1CEB7AA8-9B1C-497F-89E7-B5E9AC2A71D6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1169:*:windows:*:*:*:*:*", "matchCriteriaId": "D8C4E148-EAD0-433C-B0C3-3124B0288CC6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1195:*:windows:*:*:*:*:*", "matchCriteriaId": "1867FC4C-01BC-4FA1-B33F-66CE7D4AD9B6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1201:*:windows:*:*:*:*:*", "matchCriteriaId": "79057030-D57C-4DAC-B9F9-FE2CED222481" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1227:*:windows:*:*:*:*:*", "matchCriteriaId": "8CE03B00-0277-4738-8DA6-AFD09830B0DD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1229:*:windows:*:*:*:*:*", "matchCriteriaId": "921BC39F-E4EC-4B4C-BC7D-8002B7C3A85A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1282:*:windows:*:*:*:*:*", "matchCriteriaId": "B03B958E-8FAA-48E4-BD0D-3577B7150284" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1290:*:windows:*:*:*:*:*", "matchCriteriaId": "36902F71-4215-40B5-93B5-75A5634D4501" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1296:*:windows:*:*:*:*:*", "matchCriteriaId": "0F087F04-EF9C-43F0-95F0-36AD5182F02B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1335:*:windows:*:*:*:*:*", "matchCriteriaId": "1757311C-A432-4056-A480-12713E4E0024" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1351:*:windows:*:*:*:*:*", "matchCriteriaId": "BC6D7AC9-3351-4AE7-B2E3-00AD7C7B2E2C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1368.0:*:windows:*:*:*:*:*", "matchCriteriaId": "B660EA03-1E06-4C97-A695-B2BD668BC7E5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_professional:*:*:windows:*:*:*:*:*", "versionEndIncluding": "5.0.396.0", "matchCriteriaId": "D175167F-E8B0-4682-81AB-2D6B94FABC58" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1169:*:windows:*:*:*:*:*", "matchCriteriaId": "FC35E740-8BE7-4479-B684-6E304204B358" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1195:*:windows:*:*:*:*:*", "matchCriteriaId": "083372F2-D738-4698-97CF-F71748BE4877" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1201:*:windows:*:*:*:*:*", "matchCriteriaId": "38BAD92D-F9D8-4295-B9BD-FFB354937ED4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1227:*:windows:*:*:*:*:*", "matchCriteriaId": "0348CFA9-6DC0-4FCE-B6B8-3D0D9086471F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1229:*:windows:*:*:*:*:*", "matchCriteriaId": "03B69989-B458-4624-B40F-37A7FCD11BA9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1282:*:windows:*:*:*:*:*", "matchCriteriaId": "FA7CEE2D-C92B-45A9-89F0-42A7DFAA7DD9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1290:*:windows:*:*:*:*:*", "matchCriteriaId": "FDCB885F-8175-41B3-A6A6-1A9A3A239548" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1296:*:windows:*:*:*:*:*", "matchCriteriaId": "82039FC7-19D9-471C-A781-87D4CCE807CE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1335:*:windows:*:*:*:*:*", "matchCriteriaId": "B6D8AF4B-27E2-4A7B-A474-AF453F6A22F3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1351:*:windows:*:*:*:*:*", "matchCriteriaId": "F398BFA7-75F1-49C5-A306-820C77EEBAE2" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1356.0:*:*:*:*:*:*:*", "matchCriteriaId": "A119A362-47B2-4798-9BDF-75AB46242877" }, { "vulnerable": true, "criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1368.0:*:windows:*:*:*:*:*", "matchCriteriaId": "B8EE159F-580F-4C8E-B2EC-C01E8930B41A" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*", "matchCriteriaId": "4E545C63-FE9C-4CA1-AF0F-D999D84D2AFD" }, { "vulnerable": false, "criteria": "cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*", "matchCriteriaId": "E61F1C9B-44AF-4B35-A7B2-948EEF7639BD" } ] } ] } ], "references": [ { "url": "http://forum.avast.com/index.php?topic=55484.0", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://osvdb.org/62510", "source": "cve@mitre.org" }, { "url": "http://secunia.com/advisories/38677", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://secunia.com/advisories/38689", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/archive/1/509710/100/0/threaded", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/38363", "source": "cve@mitre.org" }, { "url": "http://www.securitytracker.com/id?1023644", "source": "cve@mitre.org" }, { "url": "http://www.trapkit.de/advisories/TKADV2010-003.txt", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2010/0449", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] } ] }