AVG Scanning Engine UPX Parsing Denial of Service Vulnerability
High Nessus Network Monitor Plugin ID 5021
SynopsisThe remote host is vulnerable to a flaw which allows malcode to be passed
DescriptionAVG Anti-Virus is installed on the remote Windows host. The version of AVG Anti-Virus installed on the remote host is affected by a flaw wherein remote attackers can bypass the scanning engine by sending specially formatted 'rar' and 'zip' archive files. An attacker, exploiting this flaw, would only need the ability to send email to valid recipients on the target server. Successful exploitation would result in the attacker being able to pass malware through the AVG server.
SolutionUpgrade to AVG 8.5 323 or later.