Memory Corruption Mach-O 2

Vulnerability

Quick Heal Internet Security Memory Corruption Vulnerability

Vulnerability Description

We found that the Quick Heal Internet Security is vulnerable to Memory Corruption while parsing malformed Mach-O file.

CVE ID

CVE-2017-8775

Vendor

http://www.quickheal.co.in/

Products

  • Quick Heal Internet Security 10.1.0.316 and prior
  • Quick Heal Total Security 10.1.0.316 and prior
  • Quick Heal AntiVirus Pro 10.1.0.316 and prior

Disclosure Timeline

  1. 25 June 2016 – Reported to vendor
  2. 5 August 2016 – Patch released

Credits

Ashfaq Ansari – Project Srishti – Payatu Technologies

 

Leave a Reply

Your email address will not be published. Required fields are marked *

seven + 8 =