PT-2008-2993 · F Secure · F-Secure Internet Security+1
Published
2008-03-20
·
Updated
2017-08-08
·
CVE-2008-1412
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
F-Secure Internet Security versions 2006 through 2008
F-Secure Anti-Virus versions 2006 through 2008
Description
The issue allows remote attackers to execute arbitrary code or cause a denial of service via a malformed archive that triggers an unhandled exception. This can be demonstrated by the PROTOS GENOME test suite for Archive Formats.
Recommendations
For F-Secure Internet Security versions 2006 through 2008, update to a version that is not affected by this issue.
For F-Secure Anti-Virus versions 2006 through 2008, update to a version that is not affected by this issue.
As a temporary workaround, consider restricting the handling of malformed archives to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
F-Secure Anti-Virus
F-Secure Internet Security