漏洞标题
MicroWord eScan 防病毒软件 VirusPopUp strcpy 堆栈溢出漏洞
漏洞描述信息
在Linux环境下发现MicroWord eScan Antivirus 7.0.32中存在一个漏洞,被定级为“危急”。该漏洞影响组件VirusPopUp中的函数strcpy,导致基于堆栈的缓冲区溢出。攻击需要本地进行。此漏洞的利用方法已被公开披露,并可能被利用。厂商已提前被联系到关于此披露问题,但没有作出任何回应。
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
跨界内存写
漏洞标题
MicroWord eScan Antivirus VirusPopUp strcpy stack-based overflow
漏洞描述信息
A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this issue is the function strcpy of the component VirusPopUp. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
漏洞类别
栈缓冲区溢出