PT-2008-4659 · Markus Oberhumer+3 · Upx+3

Published

2008-07-21

·

Updated

2017-08-08

·

CVE-2008-3243

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: F-Prot Antivirus versions prior to 6.0.9.0 F-Prot Antivirus scanning engine versions prior to 4.4.4
Description: The issue affects the scanning engine, allowing remote attackers to cause a denial of service. This can be achieved through various crafted files, including a UPX-compressed file, which triggers an engine crash, a Microsoft Office file that triggers an infinite loop, or an ASPack-compressed file, which also triggers an engine crash.
Recommendations: For F-Prot Antivirus versions prior to 6.0.9.0, update to version 6.0.9.0 or later to resolve the issue. For F-Prot Antivirus scanning engine versions prior to 4.4.4, update the scanning engine to version 4.4.4 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3243

Affected Products

Aspack
F-Prot Antivirus
Office
Upx