MEDIUM · 5.0

CVE-2010-1425

F-Secure Internet Security 2010 and earlier; Anti-Virus for Microsoft Exchange 9 and earlier, and for MIMEsweeper 5.61 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, and for Linux 4.02...

Vulnerability Description

F-Secure Internet Security 2010 and earlier; Anti-Virus for Microsoft Exchange 9 and earlier, and for MIMEsweeper 5.61 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, and for Linux 4.02 and earlier; Anti-Virus 2010 and earlier; Home Server Security 2009; Protection Service for Consumers 9 and earlier, for Business - Workstation security 9 and earlier, for Business - Server Security 8 and earlier, and for E-mail and Server security 9 and earlier; Mac Protection build 8060 and earlier; Client Security 9 and earlier; and various Anti-Virus products for Windows, Linux, and Citrix; does not properly detect malware in crafted (1) 7Z, (2) GZIP, (3) CAB, or (4) RAR archives, which makes it easier for remote attackers to avoid detection.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
F-SecureAnti-Virus<= 9.00
F-SecureF-Secure Anti-VirusAll versions
F-SecureF-Secure Anti-Virus Client SecurityAll versions
F-SecureF-Secure Anti-Virus For Citrix Servers7.00
F-SecureF-Secure Anti-Virus For LinuxAll versions
F-SecureF-Secure Anti-Virus For Microsoft Exchange6.62
F-SecureF-Secure Anti-Virus For Mimesweeper5.61
F-SecureF-Secure Anti-Virus For Windows Servers8.00
F-SecureF-Secure Anti-Virus For WorkstationsAll versions
F-SecureF-Secure Anti-Virus Linux Client SecurityAll versions
F-SecureF-Secure Anti-Virus Linux Server SecurityAll versions
F-SecureF-Secure Internet SecurityAll versions
F-SecureHome Server Security2009
F-SecureInternet Gatekeeper<= 4.02

References

FAQ

What is CVE-2010-1425?

CVE-2010-1425 is a vulnerability with a CVSS score of 5.0 (MEDIUM). F-Secure Internet Security 2010 and earlier; Anti-Virus for Microsoft Exchange 9 and earlier, and for MIMEsweeper 5.61 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, and for Linux 4.02...

How severe is CVE-2010-1425?

CVE-2010-1425 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-1425?

Check the references section above for vendor advisories and patch information. Affected products include: F-Secure Anti-Virus, F-Secure F-Secure Anti-Virus, F-Secure F-Secure Anti-Virus Client Security, F-Secure F-Secure Anti-Virus For Citrix Servers, F-Secure F-Secure Anti-Virus For Linux.