Vulnerability Description
Race condition in ESET NOD32 Antivirus before 2.2289 allows remote attackers to execute arbitrary code via a crafted CAB file, which triggers heap corruption.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eset | Nod32 Antivirus | < 2.2289 |
Related Weaknesses (CWE)
References
- http://osvdb.org/37976Broken Link
- http://secunia.com/advisories/26124Broken LinkPatchVendor Advisory
- http://securityreason.com/securityalert/2922Third Party Advisory
- http://www.eset.com/joomla/index.php?option=com_content&task=view&id=3469&ItemidBroken Link
- http://www.nruns.com/%5Bn.runs-SA-2007.016%5D%20-%20NOD32%20Antivirus%20CAB%20paBroken Link
- http://www.nruns.com/%5Bn.runs-SA-2007.016%5D%20-%20NOD32%20Antivirus%20CAB%20paBroken Link
- http://www.securityfocus.com/archive/1/474244/100/0/threadedBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/24988Broken LinkPatchThird Party Advisory
- http://www.vupen.com/english/advisories/2007/2602Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35526Third Party AdvisoryVDB Entry
- http://osvdb.org/37976Broken Link
- http://secunia.com/advisories/26124Broken LinkPatchVendor Advisory
- http://securityreason.com/securityalert/2922Third Party Advisory
- http://www.eset.com/joomla/index.php?option=com_content&task=view&id=3469&ItemidBroken Link
- http://www.nruns.com/%5Bn.runs-SA-2007.016%5D%20-%20NOD32%20Antivirus%20CAB%20paBroken Link
FAQ
What is CVE-2007-3970?
CVE-2007-3970 is a vulnerability with a CVSS score of 7.6 (HIGH). Race condition in ESET NOD32 Antivirus before 2.2289 allows remote attackers to execute arbitrary code via a crafted CAB file, which triggers heap corruption.
How severe is CVE-2007-3970?
CVE-2007-3970 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-3970?
Check the references section above for vendor advisories and patch information. Affected products include: Eset Nod32 Antivirus.