Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods.
Link | Tags |
---|---|
http://www.securitytracker.com/id?1017884 | vdb entry |
http://www.securitytracker.com/id?1017885 | vdb entry |
http://secunia.com/advisories/24778 | patch vendor advisory third party advisory |
http://www.kaspersky.com/technews?id=203038694 | patch |
http://www.zerodayinitiative.com/advisories/ZDI-07-014.html | vendor advisory |
http://www.vupen.com/english/advisories/2007/1268 | vdb entry |
http://www.securityfocus.com/bid/23345 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/33464 | vdb entry |
http://www.securityfocus.com/archive/1/464882/100/0/threaded | mailing list |