A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash the application during processing.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-49971 A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash the application during processing.
Fixes

Solution

Upgrade to the latest version of virus definitions.


Workaround

No workaround given by the vendor.

History

Fri, 08 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Avast
Avast antivirus
Avg
Avg antivirus
CPEs cpe:2.3:a:avast:antivirus:*:*:*:*:*:macos:*:*
cpe:2.3:a:avg:antivirus:*:*:*:*:*:macos:*:*
Vendors & Products Avast
Avast antivirus
Avg
Avg antivirus

Fri, 04 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Oct 2024 13:00:00 +0000

Type Values Removed Values Added
Description A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash the application during processing.
Title Uninitialized variable in digital signiture verification may crash the application
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NLOK

Published:

Updated: 2024-10-07T11:27:19.528Z

Reserved: 2024-10-03T14:29:36.984Z

Link: CVE-2024-9483

cve-icon Vulnrichment

Updated: 2024-10-04T13:35:00.944Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-04T13:15:12.980

Modified: 2024-11-08T20:54:30.980

Link: CVE-2024-9483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.