Vulnerabilities > CVE-2006-0337 - Unspecified vulnerability in F-Secure products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN f-secure
nessus
Summary
Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute arbitrary code via crafted ZIP archives.
Vulnerable Configurations
Nessus
NASL family | Windows |
NASL id | FSECURE_ARCHIVE_OVERFLOWS.NASL |
description | The version of F-Secure Anti-Virus installed on the remote Windows host is affected by multiple flaws in the way it handles ZIP and RAR archives. An attacker can exploit these, via specially crafted files, to bypass scanning or execute arbitrary code with SYSTEM privileges. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20804 |
published | 2006-01-24 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20804 |
title | F-Secure ZIP/RAR Archive Handling Overflow Multiple RCE |
code |
|
References
- http://secunia.com/advisories/18529
- http://secunia.com/advisories/18529
- http://securitytracker.com/id?1015507
- http://securitytracker.com/id?1015507
- http://securitytracker.com/id?1015508
- http://securitytracker.com/id?1015508
- http://securitytracker.com/id?1015509
- http://securitytracker.com/id?1015509
- http://securitytracker.com/id?1015510
- http://securitytracker.com/id?1015510
- http://www.ciac.org/ciac/bulletins/q-103.shtml
- http://www.ciac.org/ciac/bulletins/q-103.shtml
- http://www.f-secure.com/security/fsc-2006-1.shtml
- http://www.f-secure.com/security/fsc-2006-1.shtml
- http://www.osvdb.org/22632
- http://www.osvdb.org/22632
- http://www.securityfocus.com/bid/16309
- http://www.securityfocus.com/bid/16309
- http://www.vupen.com/english/advisories/2006/0257
- http://www.vupen.com/english/advisories/2006/0257
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24198
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24198