CVE-2005-3284
Multiple buffer overflows in AhnLab V3 AntiVirus V3Pro 2004 before 6.0.0.488, V3Net for Windows Server 6.0 before 6.0.0.488, and MyV3, with compressed file scanning enabled, allow remote attackers to execute arbitrary code via crafted (1) ALZ, (2) UUE,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.06%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple buffer overflows in AhnLab V3 AntiVirus V3Pro 2004 before 6.0.0.488, V3Net for Windows Server 6.0 before 6.0.0.488, and MyV3, with compressed file scanning enabled, allow remote attackers to execute arbitrary code via crafted (1) ALZ, (2) UUE, or (3) XXE archives.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 5.06% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- ahnlab/myv3 · ahnlab/v3net · ahnlab/v3pro 2004
- Source
- cve@mitre.org
References
- http://global.ahnlab.com/security/security_advisory002.htmlVendor Advisory
- http://secunia.com/advisories/16851Patch, Vendor Advisory
- http://secunia.com/secunia_research/2005-48/advisory/Exploit, Vendor Advisory
- http://securityreason.com/securityalert/80
- http://www.osvdb.org/19955
- http://www.securityfocus.com/archive/1/413260
- http://www.securityfocus.com/bid/15091
- http://global.ahnlab.com/security/security_advisory002.htmlVendor Advisory
- http://secunia.com/advisories/16851Patch, Vendor Advisory
- http://secunia.com/secunia_research/2005-48/advisory/Exploit, Vendor Advisory
- http://securityreason.com/securityalert/80
- http://www.osvdb.org/19955
- http://www.securityfocus.com/archive/1/413260
- http://www.securityfocus.com/bid/15091
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.