CVE-2008-1412 Information

Description

Unspecified vulnerability in multiple F-Secure anti-virus products including Internet Security 2006 through 2008 Anti-Virus 2006 through 2008 and others allows remote attackers to execute arbitrary code or cause a denial of service (hang or crash) via a malformed archive that triggers an unhandled exception as demonstrated by the PROTOS GENOME test suite for Archive Formats.

Reference

http://secunia.com/advisories/29397 http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-cs-hotfixes.shtml http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-mimesweeper-hotfixes.shtml http://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/ http://www.f-secure.com/security/fsc-2008-2.shtml http://www.securityfocus.com/bid/28282 http://www.securitytracker.com/id?1019618 http://www.securitytracker.com/id?1019619 http://www.securitytracker.com/id?1019620 http://www.vupen.com/english/advisories/2008/0903/references https://exchange.xforce.ibmcloud.com/vulnerabilities/41234

Share on: