Memory Corruption Mach-O 1

Vulnerability

Quick Heal Internet Security Memory Corruption Vulnerability

Vulnerability Description

We found that the Quick Heal Internet Security is vulnerable to Memory Corruption while parsing malformed Mach-O file.

CVE ID

CVE-2017-8774

Vendor

http://www.quickheal.co.in/

Products

  • Quick Heal Internet Security 10.1.0.316 and prior
  • Quick Heal Total Security 10.1.0.316 and prior
  • Quick Heal AntiVirus Pro 10.1.0.316 and prior

Disclosure Timeline

  1. 25 June 2016 – Reported to vendor
  2. 11 July 2016 – Patch released

Credits

Ashfaq Ansari – Project Srishti – Payatu Technologies

 

Leave a Reply

Your email address will not be published. Required fields are marked *

sixteen − 4 =