Description
Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, allows remote attackers to execute arbitrary code or cause a denial of service (hang or crash) via a malformed archive that triggers an unhandled exception, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
Affected products
- F-Secure / f-secure_anti-virus2006 – 2006
- F-Secure / f-secure_anti-virus2007 – 2007
- F-Secure / f-secure_anti-virus2007 – 2007
- F-Secure / f-secure_anti-virus2008 – 2008
- F-Secure / f-secure_anti-virus_client_security6.04
- F-Secure / f-secure_anti-virus_for_linux4.65
- F-Secure / f-secure_anti-virus_for_workstations7.11
- F-Secure / f-secure_anti-virus_linux_client_security5.54
- F-Secure / f-secure_client_security7.11
- F-Secure / f-secure_internet_security2006 – 2006
- F-Secure / f-secure_internet_security2007 – 2007
- F-Secure / f-secure_internet_security2007 – 2007
- F-Secure / f-secure_internet_security2008 – 2008
- F-Secure / f-secure_mobile_antivirus_for_s602nd_edition – 2nd_edition
- F-Secure / f-secure_mobile_antivirus_for_windows_mobile5.0 – 5.0
- F-Secure / f-secure_mobile_antivirus_for_windows_mobile6 – 6
- F-Secure / f-secure_mobile_antivirus_for_windows_mobile2003 – 2003
- F-Secure / f-secure_mobile_security_for_series_80
- F-Secure / f-secure_protection_service_for_business3.10
- F-Secure / f-secure_protection_service_for_consumers7.00
References
- MISChttp://support.f-secure.com/enu/corporate/downloads/hotfixes/av-mimesweeper-hotfixes.shtml
- MISChttp://www.f-secure.com/security/fsc-2008-2.shtml
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/41234
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2008/0903/references
- MISChttp://www.securityfocus.com/bid/28282
- MISChttp://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html
- MISChttp://support.f-secure.com/enu/corporate/downloads/hotfixes/av-cs-hotfixes.shtml
- MISChttp://www.securitytracker.com/id?1019620
- MISChttp://www.securitytracker.com/id?1019619
- MISChttp://www.securitytracker.com/id?1019618
- MISChttp://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/
- VENDOR_ADVISORYhttp://secunia.com/advisories/29397