A Windows 98 & ME forum. Win98banter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » Win98banter forum » Windows 98 » General
Site Map Home Authors List Search Today's Posts Mark Forums Read Web Partners

AVAST vulnerabilities



 
 
Thread Tools Display Modes
  #1  
Old October 5th 09, 10:57 PM posted to microsoft.public.win98.gen_discussion
MEB[_18_]
External Usenet User
 
Posts: 537
Default AVAST vulnerabilities

High Vulnerabilities

Vulnerability Summary for CVE-2009-3522
Original release date:10/01/2009
Last revised:10/02/2009
Source: US-CERT/NIST
Overview

Stack-based buffer overflow in aswMon2.sys in avast! Home and
Professional for Windows 4.8.1351, and possibly other versions before
4.8.1356, allows local users to cause a denial of service (system crash)
and possibly gain privileges via a crafted IOCTL request to IOCTL
0xb2c80018.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3522

Vulnerability Summary for CVE-2009-3524
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

Unspecified vulnerability in ashWsFtr.dll in avast! Home and
Professional for Windows before 4.8.1356 has unknown impact and local
attack vectors.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3524

MEDIUM IMPACT:

Vulnerability Summary for CVE-2009-3523
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356
does not properly validate input to IOCTLs (1) 0xb2d6000c and (2)
0xb2d60034, which allows local users to gain privileges via IOCTL
requests using crafted kernel addresses that trigger memory corruption,
a different vulnerability than CVE-2008-1625.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3523

Additional vulnerabilities not specific to AVAST may be found he
http://securitytracker.com/archives/...ingos/218.html

--
MEB
http://peoplescounsel.org/ref/windows-main.htm
Windows Info, Diagnostics, Security, Networking
http://peoplescounsel.org
The "real world" of Law, Justice, and Government
___---
  #2  
Old October 7th 09, 11:00 PM posted to microsoft.public.win98.gen_discussion
PCR
External Usenet User
 
Posts: 4,396
Default AVAST vulnerabilities

MEB wrote:
High Vulnerabilities

Vulnerability Summary for CVE-2009-3522
Original release date:10/01/2009
Last revised:10/02/2009
Source: US-CERT/NIST
Overview

Stack-based buffer overflow in aswMon2.sys in avast! Home and
Professional for Windows 4.8.1351, and possibly other versions before
4.8.1356, allows local users to cause a denial of service (system
crash) and possibly gain privileges via a crafted IOCTL request to
IOCTL 0xb2c80018.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3522

Vulnerability Summary for CVE-2009-3524
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

Unspecified vulnerability in ashWsFtr.dll in avast! Home and
Professional for Windows before 4.8.1356 has unknown impact and local
attack vectors.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3524

MEDIUM IMPACT:

Vulnerability Summary for CVE-2009-3523
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

aavmKer4.sys in avast! Home and Professional for Windows before
4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c
and (2) 0xb2d60034, which allows local users to gain privileges via
IOCTL requests using crafted kernel addresses that trigger memory
corruption, a different vulnerability than CVE-2008-1625.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3523

Additional vulnerabilities not specific to AVAST may be found he
http://securitytracker.com/archives/...ingos/218.html


That's odd, I wasn't informed there was a v.4.8.1356. But I've got it
now, thanks.

The last one I was auto-informed of was ...1351, which I finally took.
It could be as MS did -- as you said -- just before the day Win98 is
abandoned, they come out with multiple final updates.


--
Thanks or Good Luck,
There may be humor in this post, and,
Naturally, you will not sue,
Should things get worse after this,
PCR



  #3  
Old October 7th 09, 11:00 PM posted to microsoft.public.win98.gen_discussion
PCR
External Usenet User
 
Posts: 4,396
Default AVAST vulnerabilities

MEB wrote:
High Vulnerabilities

Vulnerability Summary for CVE-2009-3522
Original release date:10/01/2009
Last revised:10/02/2009
Source: US-CERT/NIST
Overview

Stack-based buffer overflow in aswMon2.sys in avast! Home and
Professional for Windows 4.8.1351, and possibly other versions before
4.8.1356, allows local users to cause a denial of service (system
crash) and possibly gain privileges via a crafted IOCTL request to
IOCTL 0xb2c80018.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3522

Vulnerability Summary for CVE-2009-3524
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

Unspecified vulnerability in ashWsFtr.dll in avast! Home and
Professional for Windows before 4.8.1356 has unknown impact and local
attack vectors.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3524

MEDIUM IMPACT:

Vulnerability Summary for CVE-2009-3523
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

aavmKer4.sys in avast! Home and Professional for Windows before
4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c
and (2) 0xb2d60034, which allows local users to gain privileges via
IOCTL requests using crafted kernel addresses that trigger memory
corruption, a different vulnerability than CVE-2008-1625.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3523

Additional vulnerabilities not specific to AVAST may be found he
http://securitytracker.com/archives/...ingos/218.html


That's odd, I wasn't informed there was a v.4.8.1356. But I've got it
now, thanks.

The last one I was auto-informed of was ...1351, which I finally took.
It could be as MS did -- as you said -- just before the day Win98 is
abandoned, they come out with multiple final updates.


--
Thanks or Good Luck,
There may be humor in this post, and,
Naturally, you will not sue,
Should things get worse after this,
PCR



  #4  
Old October 8th 09, 12:25 AM posted to microsoft.public.win98.gen_discussion
MEB[_18_]
External Usenet User
 
Posts: 537
Default AVAST vulnerabilities

On 10/07/2009 06:00 PM, PCR wrote:
MEB wrote:
High Vulnerabilities

Vulnerability Summary for CVE-2009-3522
Original release date:10/01/2009
Last revised:10/02/2009
Source: US-CERT/NIST
Overview

Stack-based buffer overflow in aswMon2.sys in avast! Home and
Professional for Windows 4.8.1351, and possibly other versions before
4.8.1356, allows local users to cause a denial of service (system
crash) and possibly gain privileges via a crafted IOCTL request to
IOCTL 0xb2c80018.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3522

Vulnerability Summary for CVE-2009-3524
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

Unspecified vulnerability in ashWsFtr.dll in avast! Home and
Professional for Windows before 4.8.1356 has unknown impact and local
attack vectors.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3524

MEDIUM IMPACT:

Vulnerability Summary for CVE-2009-3523
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

aavmKer4.sys in avast! Home and Professional for Windows before
4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c
and (2) 0xb2d60034, which allows local users to gain privileges via
IOCTL requests using crafted kernel addresses that trigger memory
corruption, a different vulnerability than CVE-2008-1625.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3523

Additional vulnerabilities not specific to AVAST may be found he
http://securitytracker.com/archives/...ingos/218.html


That's odd, I wasn't informed there was a v.4.8.1356. But I've got it
now, thanks.

The last one I was auto-informed of was ...1351, which I finally took.
It could be as MS did -- as you said -- just before the day Win98 is
abandoned, they come out with multiple final updates.



Sadly, any errors that may be in whatever becomes the "final" AVAST!
for 9X will likely be exposed within a few days or weeks as having some
form of vulnerability. Just like, should you go back to 2006 and
progress forward {time-wise} at the securitytracker link, you would find
other vulnerabilities not generally widely known. Or in an old Norton,
or any other application.

--
MEB
http://peoplescounsel.org/ref/windows-main.htm
Windows Info, Diagnostics, Security, Networking
http://peoplescounsel.org
The "real world" of Law, Justice, and Government
___---
  #5  
Old October 8th 09, 12:25 AM posted to microsoft.public.win98.gen_discussion
MEB[_18_]
External Usenet User
 
Posts: 537
Default AVAST vulnerabilities

On 10/07/2009 06:00 PM, PCR wrote:
MEB wrote:
High Vulnerabilities

Vulnerability Summary for CVE-2009-3522
Original release date:10/01/2009
Last revised:10/02/2009
Source: US-CERT/NIST
Overview

Stack-based buffer overflow in aswMon2.sys in avast! Home and
Professional for Windows 4.8.1351, and possibly other versions before
4.8.1356, allows local users to cause a denial of service (system
crash) and possibly gain privileges via a crafted IOCTL request to
IOCTL 0xb2c80018.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3522

Vulnerability Summary for CVE-2009-3524
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

Unspecified vulnerability in ashWsFtr.dll in avast! Home and
Professional for Windows before 4.8.1356 has unknown impact and local
attack vectors.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3524

MEDIUM IMPACT:

Vulnerability Summary for CVE-2009-3523
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

aavmKer4.sys in avast! Home and Professional for Windows before
4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c
and (2) 0xb2d60034, which allows local users to gain privileges via
IOCTL requests using crafted kernel addresses that trigger memory
corruption, a different vulnerability than CVE-2008-1625.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3523

Additional vulnerabilities not specific to AVAST may be found he
http://securitytracker.com/archives/...ingos/218.html


That's odd, I wasn't informed there was a v.4.8.1356. But I've got it
now, thanks.

The last one I was auto-informed of was ...1351, which I finally took.
It could be as MS did -- as you said -- just before the day Win98 is
abandoned, they come out with multiple final updates.



Sadly, any errors that may be in whatever becomes the "final" AVAST!
for 9X will likely be exposed within a few days or weeks as having some
form of vulnerability. Just like, should you go back to 2006 and
progress forward {time-wise} at the securitytracker link, you would find
other vulnerabilities not generally widely known. Or in an old Norton,
or any other application.

--
MEB
http://peoplescounsel.org/ref/windows-main.htm
Windows Info, Diagnostics, Security, Networking
http://peoplescounsel.org
The "real world" of Law, Justice, and Government
___---
  #6  
Old October 9th 09, 12:39 AM posted to microsoft.public.win98.gen_discussion
PCR
External Usenet User
 
Posts: 4,396
Default AVAST vulnerabilities

MEB wrote:
On 10/07/2009 06:00 PM, PCR wrote:
MEB wrote:
High Vulnerabilities

Vulnerability Summary for CVE-2009-3522
Original release date:10/01/2009
Last revised:10/02/2009
Source: US-CERT/NIST
Overview

Stack-based buffer overflow in aswMon2.sys in avast! Home and
Professional for Windows 4.8.1351, and possibly other versions
before
4.8.1356, allows local users to cause a denial of service (system
crash) and possibly gain privileges via a crafted IOCTL request to
IOCTL 0xb2c80018.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3522

Vulnerability Summary for CVE-2009-3524
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

Unspecified vulnerability in ashWsFtr.dll in avast! Home and
Professional for Windows before 4.8.1356 has unknown impact and
local attack vectors.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3524

MEDIUM IMPACT:

Vulnerability Summary for CVE-2009-3523
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

aavmKer4.sys in avast! Home and Professional for Windows before
4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c
and (2) 0xb2d60034, which allows local users to gain privileges via
IOCTL requests using crafted kernel addresses that trigger memory
corruption, a different vulnerability than CVE-2008-1625.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3523

Additional vulnerabilities not specific to AVAST may be found he
http://securitytracker.com/archives/...ingos/218.html


That's odd, I wasn't informed there was a v.4.8.1356. But I've got it
now, thanks.

The last one I was auto-informed of was ...1351, which I finally
took. It could be as MS did -- as you said -- just before the day
Win98 is abandoned, they come out with multiple final updates.



Sadly, any errors that may be in whatever becomes the "final" AVAST!
for 9X will likely be exposed within a few days or weeks as having
some form of vulnerability. Just like, should you go back to 2006 and
progress forward {time-wise} at the securitytracker link, you would
find other vulnerabilities not generally widely known. Or in an old
Norton, or any other application.


Well, I just got a pop-up saying my subscription would expire in 24
days -- & it asked whether I'd like to upgrade to the paying version! (1
yr. for $39.95; 3 yrs. for $57.94). All these updates & that question
STILL gives me hope avast! will continue for us! I opted just to keep
the Home Edition -- & a new reg id is on the way! (But I fully
understand your concern.)


--
Thanks or Good Luck,
There may be humor in this post, and,
Naturally, you will not sue,
Should things get worse after this,
PCR



  #7  
Old October 9th 09, 12:39 AM posted to microsoft.public.win98.gen_discussion
PCR
External Usenet User
 
Posts: 4,396
Default AVAST vulnerabilities

MEB wrote:
On 10/07/2009 06:00 PM, PCR wrote:
MEB wrote:
High Vulnerabilities

Vulnerability Summary for CVE-2009-3522
Original release date:10/01/2009
Last revised:10/02/2009
Source: US-CERT/NIST
Overview

Stack-based buffer overflow in aswMon2.sys in avast! Home and
Professional for Windows 4.8.1351, and possibly other versions
before
4.8.1356, allows local users to cause a denial of service (system
crash) and possibly gain privileges via a crafted IOCTL request to
IOCTL 0xb2c80018.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3522

Vulnerability Summary for CVE-2009-3524
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

Unspecified vulnerability in ashWsFtr.dll in avast! Home and
Professional for Windows before 4.8.1356 has unknown impact and
local attack vectors.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3524

MEDIUM IMPACT:

Vulnerability Summary for CVE-2009-3523
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

aavmKer4.sys in avast! Home and Professional for Windows before
4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c
and (2) 0xb2d60034, which allows local users to gain privileges via
IOCTL requests using crafted kernel addresses that trigger memory
corruption, a different vulnerability than CVE-2008-1625.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3523

Additional vulnerabilities not specific to AVAST may be found he
http://securitytracker.com/archives/...ingos/218.html


That's odd, I wasn't informed there was a v.4.8.1356. But I've got it
now, thanks.

The last one I was auto-informed of was ...1351, which I finally
took. It could be as MS did -- as you said -- just before the day
Win98 is abandoned, they come out with multiple final updates.



Sadly, any errors that may be in whatever becomes the "final" AVAST!
for 9X will likely be exposed within a few days or weeks as having
some form of vulnerability. Just like, should you go back to 2006 and
progress forward {time-wise} at the securitytracker link, you would
find other vulnerabilities not generally widely known. Or in an old
Norton, or any other application.


Well, I just got a pop-up saying my subscription would expire in 24
days -- & it asked whether I'd like to upgrade to the paying version! (1
yr. for $39.95; 3 yrs. for $57.94). All these updates & that question
STILL gives me hope avast! will continue for us! I opted just to keep
the Home Edition -- & a new reg id is on the way! (But I fully
understand your concern.)


--
Thanks or Good Luck,
There may be humor in this post, and,
Naturally, you will not sue,
Should things get worse after this,
PCR



  #8  
Old October 9th 09, 03:34 AM posted to microsoft.public.win98.gen_discussion
MEB[_18_]
External Usenet User
 
Posts: 537
Default AVAST vulnerabilities

On 10/08/2009 07:39 PM, PCR wrote:
MEB wrote:
On 10/07/2009 06:00 PM, PCR wrote:
MEB wrote:
High Vulnerabilities

Vulnerability Summary for CVE-2009-3522
Original release date:10/01/2009
Last revised:10/02/2009
Source: US-CERT/NIST
Overview

Stack-based buffer overflow in aswMon2.sys in avast! Home and
Professional for Windows 4.8.1351, and possibly other versions
before
4.8.1356, allows local users to cause a denial of service (system
crash) and possibly gain privileges via a crafted IOCTL request to
IOCTL 0xb2c80018.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3522

Vulnerability Summary for CVE-2009-3524
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

Unspecified vulnerability in ashWsFtr.dll in avast! Home and
Professional for Windows before 4.8.1356 has unknown impact and
local attack vectors.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3524

MEDIUM IMPACT:

Vulnerability Summary for CVE-2009-3523
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

aavmKer4.sys in avast! Home and Professional for Windows before
4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c
and (2) 0xb2d60034, which allows local users to gain privileges via
IOCTL requests using crafted kernel addresses that trigger memory
corruption, a different vulnerability than CVE-2008-1625.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3523

Additional vulnerabilities not specific to AVAST may be found he
http://securitytracker.com/archives/...ingos/218.html
That's odd, I wasn't informed there was a v.4.8.1356. But I've got it
now, thanks.

The last one I was auto-informed of was ...1351, which I finally
took. It could be as MS did -- as you said -- just before the day
Win98 is abandoned, they come out with multiple final updates.


Sadly, any errors that may be in whatever becomes the "final" AVAST!
for 9X will likely be exposed within a few days or weeks as having
some form of vulnerability. Just like, should you go back to 2006 and
progress forward {time-wise} at the securitytracker link, you would
find other vulnerabilities not generally widely known. Or in an old
Norton, or any other application.


Well, I just got a pop-up saying my subscription would expire in 24
days -- & it asked whether I'd like to upgrade to the paying version! (1
yr. for $39.95; 3 yrs. for $57.94). All these updates & that question
STILL gives me hope avast! will continue for us! I opted just to keep
the Home Edition -- & a new reg id is on the way! (But I fully
understand your concern.)



Let me know if you get any notice regarding EOS, disablement, or other
from the installation or pop-up, and I will try to keep you advised of
what is found per whatever {sub}version that should happen in, if you're
interested and not going to keep up yourself...

--
MEB
http://peoplescounsel.org/ref/windows-main.htm
Windows Info, Diagnostics, Security, Networking
http://peoplescounsel.org
The "real world" of Law, Justice, and Government
___---
  #9  
Old October 9th 09, 03:34 AM posted to microsoft.public.win98.gen_discussion
MEB[_18_]
External Usenet User
 
Posts: 537
Default AVAST vulnerabilities

On 10/08/2009 07:39 PM, PCR wrote:
MEB wrote:
On 10/07/2009 06:00 PM, PCR wrote:
MEB wrote:
High Vulnerabilities

Vulnerability Summary for CVE-2009-3522
Original release date:10/01/2009
Last revised:10/02/2009
Source: US-CERT/NIST
Overview

Stack-based buffer overflow in aswMon2.sys in avast! Home and
Professional for Windows 4.8.1351, and possibly other versions
before
4.8.1356, allows local users to cause a denial of service (system
crash) and possibly gain privileges via a crafted IOCTL request to
IOCTL 0xb2c80018.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3522

Vulnerability Summary for CVE-2009-3524
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

Unspecified vulnerability in ashWsFtr.dll in avast! Home and
Professional for Windows before 4.8.1356 has unknown impact and
local attack vectors.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3524

MEDIUM IMPACT:

Vulnerability Summary for CVE-2009-3523
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

aavmKer4.sys in avast! Home and Professional for Windows before
4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c
and (2) 0xb2d60034, which allows local users to gain privileges via
IOCTL requests using crafted kernel addresses that trigger memory
corruption, a different vulnerability than CVE-2008-1625.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3523

Additional vulnerabilities not specific to AVAST may be found he
http://securitytracker.com/archives/...ingos/218.html
That's odd, I wasn't informed there was a v.4.8.1356. But I've got it
now, thanks.

The last one I was auto-informed of was ...1351, which I finally
took. It could be as MS did -- as you said -- just before the day
Win98 is abandoned, they come out with multiple final updates.


Sadly, any errors that may be in whatever becomes the "final" AVAST!
for 9X will likely be exposed within a few days or weeks as having
some form of vulnerability. Just like, should you go back to 2006 and
progress forward {time-wise} at the securitytracker link, you would
find other vulnerabilities not generally widely known. Or in an old
Norton, or any other application.


Well, I just got a pop-up saying my subscription would expire in 24
days -- & it asked whether I'd like to upgrade to the paying version! (1
yr. for $39.95; 3 yrs. for $57.94). All these updates & that question
STILL gives me hope avast! will continue for us! I opted just to keep
the Home Edition -- & a new reg id is on the way! (But I fully
understand your concern.)



Let me know if you get any notice regarding EOS, disablement, or other
from the installation or pop-up, and I will try to keep you advised of
what is found per whatever {sub}version that should happen in, if you're
interested and not going to keep up yourself...

--
MEB
http://peoplescounsel.org/ref/windows-main.htm
Windows Info, Diagnostics, Security, Networking
http://peoplescounsel.org
The "real world" of Law, Justice, and Government
___---
  #10  
Old October 10th 09, 04:52 AM posted to microsoft.public.win98.gen_discussion
PCR
External Usenet User
 
Posts: 4,396
Default AVAST vulnerabilities

MEB wrote:
On 10/08/2009 07:39 PM, PCR wrote:
MEB wrote:
On 10/07/2009 06:00 PM, PCR wrote:
MEB wrote:
High Vulnerabilities

Vulnerability Summary for CVE-2009-3522
Original release date:10/01/2009
Last revised:10/02/2009
Source: US-CERT/NIST
Overview

Stack-based buffer overflow in aswMon2.sys in avast! Home and
Professional for Windows 4.8.1351, and possibly other versions
before
4.8.1356, allows local users to cause a denial of service (system
crash) and possibly gain privileges via a crafted IOCTL request to
IOCTL 0xb2c80018.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3522

Vulnerability Summary for CVE-2009-3524
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

Unspecified vulnerability in ashWsFtr.dll in avast! Home and
Professional for Windows before 4.8.1356 has unknown impact and
local attack vectors.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3524

MEDIUM IMPACT:

Vulnerability Summary for CVE-2009-3523
Original release date:10/01/2009
Last revised:10/05/2009
Source: US-CERT/NIST
Overview

aavmKer4.sys in avast! Home and Professional for Windows before
4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c
and (2) 0xb2d60034, which allows local users to gain privileges
via IOCTL requests using crafted kernel addresses that trigger
memory corruption, a different vulnerability than CVE-2008-1625.
http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-3523

Additional vulnerabilities not specific to AVAST may be found
he http://securitytracker.com/archives/...ingos/218.html
That's odd, I wasn't informed there was a v.4.8.1356. But I've got
it now, thanks.

The last one I was auto-informed of was ...1351, which I finally
took. It could be as MS did -- as you said -- just before the day
Win98 is abandoned, they come out with multiple final updates.


Sadly, any errors that may be in whatever becomes the "final"
AVAST! for 9X will likely be exposed within a few days or weeks as
having some form of vulnerability. Just like, should you go back to
2006 and progress forward {time-wise} at the securitytracker link,
you would find other vulnerabilities not generally widely known. Or
in an old Norton, or any other application.


Well, I just got a pop-up saying my subscription would expire in 24
days -- & it asked whether I'd like to upgrade to the paying
version! (1 yr. for $39.95; 3 yrs. for $57.94). All these updates &
that question STILL gives me hope avast! will continue for us! I
opted just to keep the Home Edition -- & a new reg id is on the way!
(But I fully understand your concern.)



Let me know if you get any notice regarding EOS, disablement, or
other from the installation or pop-up, and I will try to keep you
advised of what is found per whatever {sub}version that should happen
in, if you're interested and not going to keep up yourself...


It's a deal. The reg ID came, & avast! is back in business taking
auto-def updates.


--
Thanks or Good Luck,
There may be humor in this post, and,
Naturally, you will not sue,
Should things get worse after this,
PCR



 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
US CERT - SA08-193A Java Vulnerabilities MEB[_2_] General 0 July 12th 08 08:23 AM
US CERT - Security Alert TA08-162C -- Apple Quicktime Updates for Multiple Vulnerabilities MEB[_2_] General 7 June 19th 08 01:19 AM
Office-VISTA firewall-Adobe Flash-other vulnerabilities - US-Cert-combined MEB[_2_] General 14 December 23rd 07 07:19 AM
New IE vulnerabilities Dan General 7 May 3rd 06 06:17 PM
unpatched Critical vulnerabilities in Win 98 98SE? Dan General 0 February 13th 05 04:02 PM


All times are GMT +1. The time now is 06:35 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004-2024 Win98banter.
The comments are property of their posters.