SB2012082612 - Multiple vulnerabilities in Comodo Internet Security
Published: August 26, 2012 Updated: August 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Cryptographic issues (CVE-ID: CVE-2011-5121)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The Antivirus component in Comodo Internet Security before 5.3.175888.1227 does not properly check whether unspecified X.509 certificates are revoked, which has unknown impact and remote attack vectors.
2) Buffer overflow (CVE-ID: CVE-2011-5122)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The Antivirus component in Comodo Internet Security before 5.3.175888.1227 allows remote attackers to cause a denial of service (application crash) via a crafted compressed file.
3) Cryptographic issues (CVE-ID: CVE-2011-5123)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The Antivirus component in Comodo Internet Security before 5.3.175888.1227 does not check whether X.509 certificates in signed executable files have been revoked, which has unknown impact and remote attack vectors.
Remediation
Install update from vendor's website.