Buffer overflow in the LHA decompression component in F-Secure anti-virus...
Vulnerability Description
Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-2966
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/25426
- http://www.securitytracker.com/id?1018148
- http://securitytracker.com/id?1018147
- http://www.securitytracker.com/id?1018146
- http://www.vupen.com/english/advisories/2007/1985
- http://www.securityfocus.com/archive/1/470256/100/0/threaded
- http://www.f-secure.com/security/fsc-2007-1.shtml
- http://osvdb.org/36724
- http://www.securityfocus.com/bid/24235
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34575
- http://www.nruns.com/security_advisory_fsecure_lzh.php
More from f-secure
View All →Affected Vendor
f-secure
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.