10

CVE-2007-2967

Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.

Data is provided by the National Vulnerability Database (NVD)
F-secureF-secure Anti-virus Editionlinux_gateways Version <= 4.65
F-secureF-secure Anti-virus Editionlinux_servers Version <= 4.65
F-secureF-secure Anti-virus Editionwindows_servers Version <= 5.42
F-secureF-secure Anti-virus Editionworkstations Version <= 5.44
F-secureF-secure Anti-virus Editioncitrix_servers Version <= 5.52
F-secureF-secure Anti-virus Editionmimesweeper Version <= 5.61
F-secureF-secure Anti-virus Editionms_exchange Version <= 6.40
F-secureF-secure Anti-virus Version2005
F-secureF-secure Anti-virus Version2006
F-secureF-secure Anti-virus Version2007
F-secureF-secure Protection Service Editionconsumers Version <= 6.40
F-secureInternet Gatekeeper Editionlinux Version <= 2.16
F-secureInternet Gatekeeper Version <= 6.60
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 10.32% 0.929
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.