7.6

CVE-2008-6085

Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer overflow.

Data is provided by the National Vulnerability Database (NVD)
F-secureF-secure Anti-virus Version7.02
F-secureF-secure Anti-virus Version2006
F-secureF-secure Anti-virus Version2007
F-secureF-secure Anti-virus Version2007 Editionsecond
F-secureF-secure Anti-virus Version2008
F-secureF-secure Anti-virus Version2009
F-secureF-secure Client Security Version <= 7.12
F-secureF-secure Internet Security Version2007 Editionsecond
F-secureF-secure Linux Security Version <= 7.01
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 10.47% 0.929
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C