Directory traversal vulnerability in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to write arbitrary files via an ACE archive containing filenames with (1) .. or (2) absolute pathnames.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-07-27T04:00:00

Updated: 2024-08-07T22:22:49.059Z

Reserved: 2005-07-27T00:00:00

Link: CVE-2005-2384

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2005-07-27T04:00:00.000

Modified: 2008-09-05T20:51:37.160

Link: CVE-2005-2384

cve-icon Redhat

No data.