Integer overflow in the packed PE file parsing implementation in BitDefender products before 20060829, including Antivirus, Antivirus Plus, Internet Security, Mail Protection for Enterprises, and Online Scanner; and BitDefender products for Microsoft ISA Server and Exchange 5.5 through 2003; allows remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow, aka the cevakrnl.xmd vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bitdefender | Softwin | isa_server (including) | isa_server (including) |
Bitdefender | Softwin | ms_exchange_5.5 (including) | ms_exchange_5.5 (including) |
Bitdefender | Softwin | ms_exchange_2000 (including) | ms_exchange_2000 (including) |
Bitdefender | Softwin | ms_exchange_2003 (including) | ms_exchange_2003 (including) |
Bitdefender_antivirus | Softwin | * | * |
Bitdefender_antivirus | Softwin | plus (including) | plus (including) |
Bitdefender_internet_security | Softwin | * | * |
Bitdefender_mail_protection | Softwin | enterprises (including) | enterprises (including) |
Bitdefender_online_scanner | Softwin | * | * |