PT-2008-2993 · F Secure · F-Secure Internet Security+1

Published

2008-03-20

·

Updated

2017-08-08

·

CVE-2008-1412

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions F-Secure Internet Security versions 2006 through 2008 F-Secure Anti-Virus versions 2006 through 2008
Description The issue allows remote attackers to execute arbitrary code or cause a denial of service via a malformed archive that triggers an unhandled exception. This can be demonstrated by the PROTOS GENOME test suite for Archive Formats.
Recommendations For F-Secure Internet Security versions 2006 through 2008, update to a version that is not affected by this issue. For F-Secure Anti-Virus versions 2006 through 2008, update to a version that is not affected by this issue. As a temporary workaround, consider restricting the handling of malformed archives to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1412

Affected Products

F-Secure Anti-Virus
F-Secure Internet Security