SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-2384

Directory traversal vulnerability in a third-party compression library (UNACEV2.DLL), as used in avast!

MEDIUM 5.0EPSS 3.49%

Does this matter?

Lower severity and a low EPSS score (3.49%). Track it; it rarely justifies an emergency change on its own.

Description

Directory traversal vulnerability in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to write arbitrary files via an ACE archive containing filenames with (1) .. or (2) absolute pathnames.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
3.49% probability · 88th percentile
CISA KEV
Not listed
Affected
alwil/avast antivirus
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.