Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2008-6085


Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer overflow.


Published

2009-02-06T11:30:00.467

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.6 (HIGH)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

4.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-189

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application f-secure f-secure_anti-virus 7.02 Yes
Application f-secure f-secure_anti-virus 2006 Yes
Application f-secure f-secure_anti-virus 2007 Yes
Application f-secure f-secure_anti-virus 2007 Yes
Application f-secure f-secure_anti-virus 2008 Yes
Application f-secure f-secure_anti-virus 2009 Yes
Application f-secure f-secure_anti-virus_for_citrix_servers ≤ 7.00 Yes
Application f-secure f-secure_anti-virus_for_microsoft_exchange ≤ 7.10 Yes
Application f-secure f-secure_anti-virus_for_microsoft_exchange 6.62 Yes
Application f-secure f-secure_anti-virus_for_microsoft_exchange 7.00 Yes
Application f-secure f-secure_anti-virus_for_mimesweeper ≤ 5.61 Yes
Application f-secure f-secure_anti-virus_for_windows_servers ≤ 8.00 Yes
Application f-secure f-secure_anti-virus_for_workstations 7.10 Yes
Application f-secure f-secure_anti-virus_for_workstations 7.11 Yes
Application f-secure f-secure_anti-virus_linux_client_security ≤ 5.54 Yes
Application f-secure f-secure_anti-virus_linux_client_security 5.30 Yes
Application f-secure f-secure_anti-virus_linux_client_security 5.52 Yes
Application f-secure f-secure_anti-virus_linux_client_security 5.53 Yes
Application f-secure f-secure_anti-virus_linux_server_security ≤ 5.54 Yes
Application f-secure f-secure_anti-virus_linux_server_security 5.30 Yes
Application f-secure f-secure_anti-virus_linux_server_security 5.52 Yes
Application f-secure f-secure_client_security ≤ 7.12 Yes
Application f-secure f-secure_client_security 7.11 Yes
Application f-secure f-secure_home_server_security 2009 Yes
Application f-secure f-secure_internet_gatekeeper_for_linux ≤ 2.16 Yes
Application f-secure f-secure_internet_gatekeeper_for_windows ≤ 6.61 Yes
Application f-secure f-secure_internet_security 7.02 Yes
Application f-secure f-secure_internet_security 2006 Yes
Application f-secure f-secure_internet_security 2007 Yes
Application f-secure f-secure_internet_security 2007 Yes
Application f-secure f-secure_internet_security 2008 Yes
Application f-secure f-secure_internet_security 2009 Yes
Application f-secure f-secure_linux_security ≤ 7.01 Yes
Application f-secure f-secure_messaging_security_gateway ≤ 5.0.4 Yes
Application f-secure f-secure_messaging_security_gateway 4.0.7 Yes
Application f-secure f-secure_protection_service_for_business ≤ 3.10 Yes
Application f-secure f-secure_protection_service_for_business 3.00 Yes
Application f-secure f-secure_protection_service_for_consumers ≤ 8.00 Yes
Application f-secure f-secure_protection_service_for_consumers 5.00 Yes
Application f-secure f-secure_protection_service_for_consumers 6.00 Yes
Application f-secure f-secure_protection_service_for_consumers 7.00 Yes

References