7.5

CVE-2007-2966

Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F-secure ≫ F-secure Anti-virus Edition linux_gateways Version <= 4.65
F-secure ≫ F-secure Anti-virus Edition linux_servers Version <= 4.65
F-secure ≫ F-secure Anti-virus Edition windows_servers Version <= 5.42
F-secure ≫ F-secure Anti-virus Edition workstations Version <= 5.44
F-secure ≫ F-secure Anti-virus Edition citrix_servers Version <= 5.52
F-secure ≫ F-secure Anti-virus Edition mimesweeper Version <= 5.61
F-secure ≫ F-secure Anti-virus Edition ms_exchange Version <= 6.40
F-secure ≫ F-secure Anti-virus Version 2005
F-secure ≫ F-secure Anti-virus Version 2006
F-secure ≫ F-secure Anti-virus Version 2007
F-secure ≫ F-secure Protection Service Edition consumers Version <= 6.40
F-secure ≫ Internet Gatekeeper Edition linux Version <= 2.16
F-secure ≫ Internet Gatekeeper Version <= 6.60
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.21% 0.914
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://www.securitytracker.com/id?1018146
http://www.securitytracker.com/id?1018148
http://www.vupen.com/english/advisories/2007/1985
http://osvdb.org/36724
http://secunia.com/advisories/25426
Patch
Vendor Advisory
http://securitytracker.com/id?1018147
http://www.f-secure.com/security/fsc-2007-1.shtml
Patch
Vendor Advisory
http://www.nruns.com/security_advisory_fsecure_lzh.php
http://www.securityfocus.com/archive/1/470256/100/0/threaded
http://www.securityfocus.com/bid/24235
https://exchange.xforce.ibmcloud.com/vulnerabilities/34575