CVE-2008-6085 - CVE House
Back to Database
Status published High CVE-2008-6085

Integer overflow in multiple F-Secure anti-virus products, including Internet Security...

Vulnerability Description

Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer overflow.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-6085

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

f-secure anti-virus, f-secure anti-virus for citrix servers, f-secure anti-virus for microsoft exchange, f-secure anti-virus for mimesweeper, f-secure anti-virus for windows servers, f-secure anti-virus for workstations, f-secure anti-virus linux client security, f-secure anti-virus linux server security, f-secure client security, f-secure home server security, f-secure internet gatekeeper for linux, f-secure internet gatekeeper for windows, f-secure internet security, f-secure linux security, f-secure messaging security gateway, f-secure protection service for business, f-secure protection service for consumers
Vulnerable Versions:
7.02, 2006, 2007, 2008, 2009, 0, 6.62, 7.00, 7.10, 7.11, 5.30, 5.52, 5.53, 4.0.7, 3.00, 5.00, 6.00

Timeline

Official Publish: February 6th, 2009
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.