CVE-2008-6085

Published Feb 6, 2009

Last updated 4 months ago

Overview

Description
Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer overflow.
Source
cve@mitre.org
NVD status
Modified
Products
f-secure_anti-virus, f-secure_anti-virus_for_citrix_servers, f-secure_anti-virus_for_microsoft_exchange, f-secure_anti-virus_for_mimesweeper, f-secure_anti-virus_for_windows_servers, f-secure_anti-virus_for_workstations, f-secure_anti-virus_linux_client_security, f-secure_anti-virus_linux_server_security, f-secure_client_security, f-secure_home_server_security, f-secure_internet_gatekeeper_for_linux, f-secure_internet_gatekeeper_for_windows, f-secure_internet_security, f-secure_linux_security, f-secure_messaging_security_gateway, f-secure_protection_service_for_business, f-secure_protection_service_for_consumers

Risk scores

CVSS 2.0

Type
Primary
Base score
7.6
Impact score
10
Exploitability score
4.9
Vector string
AV:N/AC:H/Au:N/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
CWE-189

Social media

Hype score
Not currently trending

Configurations