Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary code via a crafted LC_UNIXTHREAD.cmdsize field in a Mach-O file that is mishandled during a Security Scan (aka Custom Scan) operation.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/95194 | vdb entry third party advisory |
http://www.securitytracker.com/id/1037547 | vdb entry third party advisory |
https://www.youtube.com/watch?v=h9LOsv4XE00 | third party advisory exploit |
https://github.com/payatu/QuickHeal | third party advisory exploit |