2024-04-04 08:46:00 +00:00

262 lines
9.7 KiB
JSON

{
"id": "CVE-2010-0705",
"sourceIdentifier": "cve@mitre.org",
"published": "2010-02-25T18:30:00.377",
"lastModified": "2018-10-10T19:53:24.980",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption."
},
{
"lang": "es",
"value": "Aavmker4.sys en avast! desde v4.8 hasta v4.8.1368.0 y v5.0 anteriores a v5.0.418.0 corriendo sobre Windows 2000 o XP, no valida adecuadamente una entrada a IOCTL 0xb2d60030, lo que permite a usuarios locales producir una denegaci\u00f3n de servicio (ca\u00edda del sistema) o ejecutar c\u00f3digo arbitrario para ganar privilegios a trav\u00e9s de peticiones IOCTL utilizando direcciones de kernel manipuladas que inician una corrupci\u00f3n de memoria."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 7.2
},
"baseSeverity": "HIGH",
"exploitabilityScore": 3.9,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_home:*:*:windows:*:*:*:*:*",
"versionEndIncluding": "5.0.396.0",
"matchCriteriaId": "1CEB7AA8-9B1C-497F-89E7-B5E9AC2A71D6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1169:*:windows:*:*:*:*:*",
"matchCriteriaId": "D8C4E148-EAD0-433C-B0C3-3124B0288CC6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1195:*:windows:*:*:*:*:*",
"matchCriteriaId": "1867FC4C-01BC-4FA1-B33F-66CE7D4AD9B6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1201:*:windows:*:*:*:*:*",
"matchCriteriaId": "79057030-D57C-4DAC-B9F9-FE2CED222481"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1227:*:windows:*:*:*:*:*",
"matchCriteriaId": "8CE03B00-0277-4738-8DA6-AFD09830B0DD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1229:*:windows:*:*:*:*:*",
"matchCriteriaId": "921BC39F-E4EC-4B4C-BC7D-8002B7C3A85A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1282:*:windows:*:*:*:*:*",
"matchCriteriaId": "B03B958E-8FAA-48E4-BD0D-3577B7150284"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1290:*:windows:*:*:*:*:*",
"matchCriteriaId": "36902F71-4215-40B5-93B5-75A5634D4501"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1296:*:windows:*:*:*:*:*",
"matchCriteriaId": "0F087F04-EF9C-43F0-95F0-36AD5182F02B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1335:*:windows:*:*:*:*:*",
"matchCriteriaId": "1757311C-A432-4056-A480-12713E4E0024"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1351:*:windows:*:*:*:*:*",
"matchCriteriaId": "BC6D7AC9-3351-4AE7-B2E3-00AD7C7B2E2C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_home:4.8.1368.0:*:windows:*:*:*:*:*",
"matchCriteriaId": "B660EA03-1E06-4C97-A695-B2BD668BC7E5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_professional:*:*:windows:*:*:*:*:*",
"versionEndIncluding": "5.0.396.0",
"matchCriteriaId": "D175167F-E8B0-4682-81AB-2D6B94FABC58"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1169:*:windows:*:*:*:*:*",
"matchCriteriaId": "FC35E740-8BE7-4479-B684-6E304204B358"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1195:*:windows:*:*:*:*:*",
"matchCriteriaId": "083372F2-D738-4698-97CF-F71748BE4877"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1201:*:windows:*:*:*:*:*",
"matchCriteriaId": "38BAD92D-F9D8-4295-B9BD-FFB354937ED4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1227:*:windows:*:*:*:*:*",
"matchCriteriaId": "0348CFA9-6DC0-4FCE-B6B8-3D0D9086471F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1229:*:windows:*:*:*:*:*",
"matchCriteriaId": "03B69989-B458-4624-B40F-37A7FCD11BA9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1282:*:windows:*:*:*:*:*",
"matchCriteriaId": "FA7CEE2D-C92B-45A9-89F0-42A7DFAA7DD9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1290:*:windows:*:*:*:*:*",
"matchCriteriaId": "FDCB885F-8175-41B3-A6A6-1A9A3A239548"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1296:*:windows:*:*:*:*:*",
"matchCriteriaId": "82039FC7-19D9-471C-A781-87D4CCE807CE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1335:*:windows:*:*:*:*:*",
"matchCriteriaId": "B6D8AF4B-27E2-4A7B-A474-AF453F6A22F3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1351:*:windows:*:*:*:*:*",
"matchCriteriaId": "F398BFA7-75F1-49C5-A306-820C77EEBAE2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1356.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A119A362-47B2-4798-9BDF-75AB46242877"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:avast:avast_antivirus_professional:4.8.1368.0:*:windows:*:*:*:*:*",
"matchCriteriaId": "B8EE159F-580F-4C8E-B2EC-C01E8930B41A"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*",
"matchCriteriaId": "4E545C63-FE9C-4CA1-AF0F-D999D84D2AFD"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E61F1C9B-44AF-4B35-A7B2-948EEF7639BD"
}
]
}
]
}
],
"references": [
{
"url": "http://forum.avast.com/index.php?topic=55484.0",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://osvdb.org/62510",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/38677",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/38689",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/archive/1/509710/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/38363",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1023644",
"source": "cve@mitre.org"
},
{
"url": "http://www.trapkit.de/advisories/TKADV2010-003.txt",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2010/0449",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
}
]
}