CVE ID | CVE-2015-7303 |
CVSS SCORE | 9.3, AV:N/AC:M/Au:N/C:C/I:C/A:C |
AFFECTED VENDORS |
Avira |
AFFECTED PRODUCTS |
Management Console |
VULNERABILITY DETAILS |
The specific flaw exists within the handling of HTTP headers by the Update Manager service. By sending overly large headers, an attacker is able to cause memory to be reused after it has been released. An attacker could leverage this to execute arbitrary code under the context of SYSTEM. |
ADDITIONAL DETAILS |
09/03/2015 - ZDI emailed Avira contact and requested contact -- Mitigation: -- Vendor Patch: http://www.avira.com/en/support-for-home-knowledgebase-detail/kbid/1787
|
DISCLOSURE TIMELINE |
|
CREDIT | rgod |