Vulnerability Description
The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, probably related to invalid offsets.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F-Prot | F-Prot Antivirus | 6.2.1.4252 |
| F-Prot | Scanning Engine | 4.4.4.56 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2008/Jul/0569.html
- http://secunia.com/advisories/31313Vendor Advisory
- http://www.securityfocus.com/bid/30461
- http://www.securitytracker.com/id?1020612
- http://www.vupen.com/english/advisories/2008/2283
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44134
- https://www.exploit-db.com/exploits/6174
- http://seclists.org/fulldisclosure/2008/Jul/0569.html
- http://secunia.com/advisories/31313Vendor Advisory
- http://www.securityfocus.com/bid/30461
- http://www.securitytracker.com/id?1020612
- http://www.vupen.com/english/advisories/2008/2283
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44134
- https://www.exploit-db.com/exploits/6174
FAQ
What is CVE-2008-3447?
CVE-2008-3447 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, probably related to invalid offsets.
How severe is CVE-2008-3447?
CVE-2008-3447 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-3447?
Check the references section above for vendor advisories and patch information. Affected products include: F-Prot F-Prot Antivirus, F-Prot Scanning Engine.