PT-2008-4659 · Markus Oberhumer+3 · Upx+3
Published
2008-07-21
·
Updated
2017-08-08
·
CVE-2008-3243
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
F-Prot Antivirus versions prior to 6.0.9.0
F-Prot Antivirus scanning engine versions prior to 4.4.4
Description:
The issue affects the scanning engine, allowing remote attackers to cause a denial of service. This can be achieved through various crafted files, including a UPX-compressed file, which triggers an engine crash, a Microsoft Office file that triggers an infinite loop, or an ASPack-compressed file, which also triggers an engine crash.
Recommendations:
For F-Prot Antivirus versions prior to 6.0.9.0, update to version 6.0.9.0 or later to resolve the issue.
For F-Prot Antivirus scanning engine versions prior to 4.4.4, update the scanning engine to version 4.4.4 or later to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aspack
F-Prot Antivirus
Office
Upx