Vulnerability Description
Integer overflow in aswFW.sys 5.0.594.0 in Avast! Internet Security 5.0 Korean Trial allows local users to cause a denial of service (memory corruption and panic) via a crafted IOCTL_ASWFW_COMM_PIDINFO_RESULTS DeviceIoControl request to \\.\aswFW.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avast\! | Avast\! Internet Security | 5.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/42148Exploit
- http://x90c.blogspot.com/2011/11/avast-internet-security-aswfwsys-ioctl.html
- http://x90c.blogspot.com/2011/12/bid-42148-my-avast-kernel-driver-0day_01.html
- https://web.archive.org/web/20120228033302/http://www.x90c.org/advisories/avast_Exploit
- http://www.securityfocus.com/bid/42148Exploit
- http://x90c.blogspot.com/2011/11/avast-internet-security-aswfwsys-ioctl.html
- http://x90c.blogspot.com/2011/12/bid-42148-my-avast-kernel-driver-0day_01.html
- https://web.archive.org/web/20120228033302/http://www.x90c.org/advisories/avast_Exploit
FAQ
What is CVE-2010-5075?
CVE-2010-5075 is a vulnerability with a CVSS score of 2.1 (LOW). Integer overflow in aswFW.sys 5.0.594.0 in Avast! Internet Security 5.0 Korean Trial allows local users to cause a denial of service (memory corruption and panic) via a crafted IOCTL_ASWFW_COMM_PIDINF...
How severe is CVE-2010-5075?
CVE-2010-5075 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-5075?
Check the references section above for vendor advisories and patch information. Affected products include: Avast\! Avast\! Internet Security.