PT-2007-2941 · F Secure · F-Secure Anti-Virus Client Security

Published

2007-03-21

·

Updated

2018-10-16

·

CVE-2007-1557

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions F-Secure Anti-Virus Client Security version 6.02
Description A format string issue allows local users to cause a denial of service and possibly gain privileges via format string specifiers in the Management Server name field on the Communication settings page.
Recommendations For F-Secure Anti-Virus Client Security version 6.02, avoid using format string specifiers in the Management Server name field until a fix is available. As a temporary workaround, consider restricting access to the Communication settings page to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1557

Affected Products

F-Secure Anti-Virus Client Security