Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security...
Vulnerability Description
Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, allows remote attackers to execute arbitrary code or cause a denial of service (hang or crash) via a malformed archive that triggers an unhandled exception, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-1412
Credits & Attribution
No credits recorded in the NVD database.
References
- http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-mimesweeper-hotfixes.shtml
- http://www.f-secure.com/security/fsc-2008-2.shtml
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41234
- http://www.vupen.com/english/advisories/2008/0903/references
- http://www.securityfocus.com/bid/28282
- http://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html
- http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-cs-hotfixes.shtml
- http://www.securitytracker.com/id?1019620
- http://www.securitytracker.com/id?1019619
- http://www.securitytracker.com/id?1019618
- http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/
- http://secunia.com/advisories/29397
More from f-secure
View All →Affected Vendor
f-secure
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.