An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed xar file to crash the application during file processing.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-49972 An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed xar file to crash the application during file processing.
Fixes

Solution

Upgrade to the latest version of virus definitions.


Workaround

No workaround given by the vendor.

History

Fri, 08 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Avast
Avast antivirus
Avg
Avg antivirus
CPEs cpe:2.3:a:avast:antivirus:*:*:*:*:*:macos:*:*
cpe:2.3:a:avg:antivirus:*:*:*:*:*:macos:*:*
Vendors & Products Avast
Avast antivirus
Avg
Avg antivirus

Fri, 04 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Oct 2024 13:00:00 +0000

Type Values Removed Values Added
Description An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed xar file to crash the application during file processing.
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NLOK

Published:

Updated: 2024-10-07T11:27:37.651Z

Reserved: 2024-10-03T14:29:40.798Z

Link: CVE-2024-9484

cve-icon Vulnrichment

Updated: 2024-10-04T13:31:42.859Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-04T13:15:13.167

Modified: 2024-11-08T20:55:14.283

Link: CVE-2024-9484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.