CVE-2017-5005
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary code via a crafted LC_UNIXTHREAD.cmdsize field in a Mach-O file that is mishandled during a Security Scan (aka Custom Scan) operation.
Desbordamiento de búfer basado en pila en Quick Heal Internet Security 10.1.0.316 y versiones anteriores, Total Security 10.1.0.316 y versiones anteriores y AntiVirus Pro 10.1.0.316 y versiones anteriores en OS X permite a atacantes remotos ejecutar código arbitrario a través de un campo LC_UNIXTHREAD.cmdsize manipulado en un archivo Mach-O que no es manejado correctamente durante una operación Security Scan (también conocido como Custom Scan).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-01-02 CVE Reserved
- 2017-01-02 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-08-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/95194 | Third Party Advisory | |
http://www.securitytracker.com/id/1037547 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/payatu/QuickHeal | 2024-08-05 | |
https://www.youtube.com/watch?v=h9LOsv4XE00 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Quickheal Search vendor "Quickheal" | Antivirus Pro Search vendor "Quickheal" for product "Antivirus Pro" | <= 10.1.0.316 Search vendor "Quickheal" for product "Antivirus Pro" and version " <= 10.1.0.316" | - |
Affected
| ||||||
Quickheal Search vendor "Quickheal" | Internet Security Search vendor "Quickheal" for product "Internet Security" | <= 10.1.0.316 Search vendor "Quickheal" for product "Internet Security" and version " <= 10.1.0.316" | - |
Affected
| ||||||
Quickheal Search vendor "Quickheal" | Total Security Search vendor "Quickheal" for product "Total Security" | <= 10.1.0.316 Search vendor "Quickheal" for product "Total Security" and version " <= 10.1.0.316" | - |
Affected
|