Vulnerabilities > CVE-2008-1412 - Unspecified vulnerability in F-Secure products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN f-secure
nessus
Summary
Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, allows remote attackers to execute arbitrary code or cause a denial of service (hang or crash) via a malformed archive that triggers an unhandled exception, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
Vulnerable Configurations
Nessus
NASL family | Windows |
NASL id | FSECURE_FSC_2008_02.NASL |
description | The version of F-Secure Anti-Virus installed on the remote host fails to handle specially crafted archives. A remote attacker can exploit this issue to crash the application or execute arbitrary code with SYSTEM privileges. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 31682 |
published | 2008-03-28 |
reporter | This script is Copyright (C) 2008-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/31682 |
title | F-Secure Archive Handling RCE (FSC-2008-2) |
code |
|
References
- http://secunia.com/advisories/29397
- http://secunia.com/advisories/29397
- http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-cs-hotfixes.shtml
- http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-cs-hotfixes.shtml
- http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-mimesweeper-hotfixes.shtml
- http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-mimesweeper-hotfixes.shtml
- http://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html
- http://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html
- http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/
- http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/
- http://www.f-secure.com/security/fsc-2008-2.shtml
- http://www.f-secure.com/security/fsc-2008-2.shtml
- http://www.securityfocus.com/bid/28282
- http://www.securityfocus.com/bid/28282
- http://www.securitytracker.com/id?1019618
- http://www.securitytracker.com/id?1019618
- http://www.securitytracker.com/id?1019619
- http://www.securitytracker.com/id?1019619
- http://www.securitytracker.com/id?1019620
- http://www.securitytracker.com/id?1019620
- http://www.vupen.com/english/advisories/2008/0903/references
- http://www.vupen.com/english/advisories/2008/0903/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41234
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41234