CVE-2008-1412

Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, allows remote attackers to execute arbitrary code or cause a denial of service (hang or crash) via a malformed archive that triggers an unhandled exception, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f-secure:f-secure_anti-virus:2006:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_anti-virus:2007:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_anti-virus:2007:second_edition:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_anti-virus:2008:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_anti-virus_client_security:*:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_anti-virus_for_linux:*:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_anti-virus_for_workstations:*:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_anti-virus_linux_client_security:*:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_client_security:*:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_internet_security:2006:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_internet_security:2007:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_internet_security:2007:second_edition:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_internet_security:2008:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_mobile_antivirus_for_s60:2nd_edition:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_mobile_antivirus_for_windows_mobile:5.0:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_mobile_antivirus_for_windows_mobile:6:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_mobile_antivirus_for_windows_mobile:2003:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_mobile_security_for_series_80:*:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_protection_service_for_business:*:*:*:*:*:*:*:*
cpe:2.3:a:f-secure:f-secure_protection_service_for_consumers:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:44

Type Values Removed Values Added
References () http://secunia.com/advisories/29397 - Vendor Advisory () http://secunia.com/advisories/29397 - Vendor Advisory
References () http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-cs-hotfixes.shtml - () http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-cs-hotfixes.shtml -
References () http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-mimesweeper-hotfixes.shtml - () http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-mimesweeper-hotfixes.shtml -
References () http://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html - () http://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html -
References () http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/ - () http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/ -
References () http://www.f-secure.com/security/fsc-2008-2.shtml - Patch () http://www.f-secure.com/security/fsc-2008-2.shtml - Patch
References () http://www.securityfocus.com/bid/28282 - () http://www.securityfocus.com/bid/28282 -
References () http://www.securitytracker.com/id?1019618 - () http://www.securitytracker.com/id?1019618 -
References () http://www.securitytracker.com/id?1019619 - () http://www.securitytracker.com/id?1019619 -
References () http://www.securitytracker.com/id?1019620 - () http://www.securitytracker.com/id?1019620 -
References () http://www.vupen.com/english/advisories/2008/0903/references - () http://www.vupen.com/english/advisories/2008/0903/references -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/41234 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/41234 -

Information

Published : 2008-03-20 10:44

Updated : 2024-11-21 00:44


NVD link : CVE-2008-1412

Mitre link : CVE-2008-1412

CVE.ORG link : CVE-2008-1412


JSON object : View

Products Affected

f-secure

  • f-secure_anti-virus
  • f-secure_protection_service_for_business
  • f-secure_mobile_antivirus_for_windows_mobile
  • f-secure_anti-virus_for_linux
  • f-secure_internet_security
  • f-secure_mobile_antivirus_for_s60
  • f-secure_anti-virus_linux_client_security
  • f-secure_mobile_security_for_series_80
  • f-secure_protection_service_for_consumers
  • f-secure_anti-virus_client_security
  • f-secure_anti-virus_for_workstations
  • f-secure_client_security
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo