HIGH · 7.6

CVE-2008-6085

Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, ...

Vulnerability Description

Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer overflow.

CVSS Score

7.6

HIGH

AV:N/AC:H/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
F-SecureF-Secure Anti-Virus7.02
F-SecureF-Secure Anti-Virus For Citrix Servers<= 7.00
F-SecureF-Secure Anti-Virus For Microsoft Exchange<= 7.10
F-SecureF-Secure Anti-Virus For Mimesweeper<= 5.61
F-SecureF-Secure Anti-Virus For Windows Servers<= 8.00
F-SecureF-Secure Anti-Virus For Workstations7.10
F-SecureF-Secure Anti-Virus Linux Client Security<= 5.54
F-SecureF-Secure Anti-Virus Linux Server Security<= 5.54
F-SecureF-Secure Client Security<= 7.12
F-SecureF-Secure Home Server Security2009
F-SecureF-Secure Internet Gatekeeper For Linux<= 2.16
F-SecureF-Secure Internet Gatekeeper For Windows<= 6.61
F-SecureF-Secure Internet Security7.02
F-SecureF-Secure Linux Security<= 7.01
F-SecureF-Secure Messaging Security Gateway<= 5.0.4
F-SecureF-Secure Protection Service For Business<= 3.10
F-SecureF-Secure Protection Service For Consumers<= 8.00

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-6085?

CVE-2008-6085 is a vulnerability with a CVSS score of 7.6 (HIGH). Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, ...

How severe is CVE-2008-6085?

CVE-2008-6085 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-6085?

Check the references section above for vendor advisories and patch information. Affected products include: F-Secure F-Secure Anti-Virus, F-Secure F-Secure Anti-Virus For Citrix Servers, F-Secure F-Secure Anti-Virus For Microsoft Exchange, F-Secure F-Secure Anti-Virus For Mimesweeper, F-Secure F-Secure Anti-Virus For Windows Servers.