Back to Database
Status published
Critical
CVE-2007-2974
Buffer overflow in the file parsing engine in Avira Antivir...
Vulnerability Description
Buffer overflow in the file parsing engine in Avira Antivir Antivirus before 7.03.00.09 allows remote attackers to execute arbitrary code via a crafted LZH archive file, resulting from an "integer cast around."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-2974
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.nruns.com/advisories/%5Bn.runs-SA-2007.010%5D%20-%20Avira%20Antivir%20Antivirus%20LZH%20parsing%20Arbitrary%20Code%20Execution%20Advisory.txt
- http://www.securityfocus.com/bid/24187
- http://forum.antivir-pe.de/thread.php?threadid=22528
- http://www.vupen.com/english/advisories/2007/1971
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063624.html
- http://osvdb.org/36712
- http://securityreason.com/securityalert/2764
- http://secunia.com/advisories/25417
- http://www.securityfocus.com/archive/1/469805/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34551
- http://securitytracker.com/id?1018131
More from avira
View All →CVE-2020-9320
Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a...
Medium
5.5
CVE-2020-8961
An issue was discovered in Avira Free-Antivirus before 15.0.2004.1825. The...
Critical
9.8
CVE-2020-12680
Avira Free Antivirus through 15.0.2005.1866 allows local users to discover...
Medium
5.5
CVE-2020-12463
An elevation of privilege vulnerability exists in Avira Software Updater...
High
7.8
CVE-2020-12254
Avira Antivirus before 5.0.2003.1821 on Windows allows privilege escalation or...
High
7.8
Affected Vendor
avira
View all reports →Affected Software
antivir, av pack
Vulnerable Versions:
0
Timeline
Official Publish:
June 1st, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.