Vulnerability Description
Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data via malformed (1) RAR and (2) ZIP archives, which are not properly scanned.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F-Secure | F-Secure Anti-Virus | 4.51 |
| F-Secure | F-Secure Internet Security | 2004 |
| F-Secure | F-Secure Personal Express | 4.5 |
| F-Secure | Internet Gatekeeper | 2.06 |
References
- http://secunia.com/advisories/18529PatchVendor Advisory
- http://securitytracker.com/id?1015507
- http://securitytracker.com/id?1015508
- http://securitytracker.com/id?1015509
- http://securitytracker.com/id?1015510
- http://www.ciac.org/ciac/bulletins/q-103.shtml
- http://www.f-secure.com/security/fsc-2006-1.shtmlPatch
- http://www.osvdb.org/22633
- http://www.securityfocus.com/bid/16309Patch
- http://www.vupen.com/english/advisories/2006/0257
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24199
- http://secunia.com/advisories/18529PatchVendor Advisory
- http://securitytracker.com/id?1015507
- http://securitytracker.com/id?1015508
- http://securitytracker.com/id?1015509
FAQ
What is CVE-2006-0338?
CVE-2006-0338 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Ser...
How severe is CVE-2006-0338?
CVE-2006-0338 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-0338?
Check the references section above for vendor advisories and patch information. Affected products include: F-Secure F-Secure Anti-Virus, F-Secure F-Secure Internet Security, F-Secure F-Secure Personal Express, F-Secure Internet Gatekeeper.