Summary
Detail | |||
---|---|---|---|
Vendor | F-Secure | First view | 2004-08-18 |
Product | F-Secure Anti-Virus | Last view | 2010-04-15 |
Version | 5.41 | Type | Application |
Update | * | ||
Edition | workstations | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:f-secure:f-secure_anti-virus |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
5 | 2010-04-15 | CVE-2010-1425 | F-Secure Internet Security 2010 and earlier; Anti-Virus for Microsoft Exchange 9 and earlier, and for MIMEsweeper 5.61 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, and for Linux 4.02 and earlier; Anti-Virus 2010 and earlier; Home Server Security 2009; Protection Service for Consumers 9 and earlier, for Business - Workstation security 9 and earlier, for Business - Server Security 8 and earlier, and for E-mail and Server security 9 and earlier; Mac Protection build 8060 and earlier; Client Security 9 and earlier; and various Anti-Virus products for Windows, Linux, and Citrix; does not properly detect malware in crafted (1) 7Z, (2) GZIP, (3) CAB, or (4) RAR archives, which makes it easier for remote attackers to avoid detection. |
9.3 | 2007-06-20 | CVE-2007-3300 | Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive. |
10 | 2007-05-31 | CVE-2007-2967 | Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files. |
7.5 | 2007-05-31 | CVE-2007-2966 | Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335. |
7.2 | 2007-05-31 | CVE-2007-2965 | Unspecified vulnerability in the Real-time Scanning component in multiple F-Secure products, including Internet Security 2005, 2006 and 2007; Anti-Virus 2005, 2006 and 2007; and Solutions based on F-Secure Protection Service for Consumers 6.40 and earlier allows local users to gain privileges via a crafted I/O request packet (IRP), related to IOCTL (Input/Output Control) and "access validation of the address space." |
5 | 2006-07-10 | CVE-2006-3490 | F-Secure Anti-Virus 2003 through 2006 and other versions, Internet Security 2003 through 2006, and Service Platform for Service Providers 6.x and earlier does not scan files contained on removable media when "Scan network drives" is disabled, which allows remote attackers to bypass anti-virus controls. |
5 | 2006-07-10 | CVE-2006-3489 | F-Secure Anti-Virus 2003 through 2006 and other versions, Internet Security 2003 through 2006, and Service Platform for Service Providers 6.x and earlier allows remote attackers to bypass anti-virus scanning via a crafted filename. |
5 | 2006-01-20 | CVE-2006-0338 | Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data via malformed (1) RAR and (2) ZIP archives, which are not properly scanned. |
7.5 | 2006-01-20 | CVE-2006-0337 | Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute arbitrary code via crafted ZIP archives. |
7.5 | 2005-05-02 | CVE-2005-0350 | Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows remote attackers to execute arbitrary code via a crafted ARJ archive. |
5 | 2004-12-31 | CVE-2004-2442 | Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on the target system. |
6.4 | 2004-12-31 | CVE-2004-2405 | Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote attackers to bypass scanning or cause a denial of service (crash or module restart), depending on the product, via a malformed LHA archive. |
6.4 | 2004-08-18 | CVE-2004-0235 | Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path"). |
10 | 2004-08-18 | CVE-2004-0234 | Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
66% (2) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
33% (1) | CWE-20 | Improper Input Validation |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
63811 | F-Secure Multiple Products Multiple Archive Files Detection Bypass |
36729 | F-Secure Anti-Virus Crafted RAR File Scanning Bypass |
36728 | F-Secure Anti-Virus Crafted LHA File Scanning Bypass |
36727 | F-Secure Multiple Products Real-time Scanning Component Crafted IRP Packet L... |
36726 | F-Secure Anti-Virus FSG File Handling DoS |
36725 | F-Secure Anti-Virus ARJ File Handling DoS |
36724 | F-Secure Anti-Virus LHA Decompresion Component File Handling Overflow |
26876 | F-Secure Antivirus Removable Media Scan Failure |
26875 | F-Secure Antivirus Crafted Executable Name Scan Bypass |
22633 | F-Secure Anti-Virus Crafted ZIP/RAR Scanner Bypass |
22632 | F-Secure Anti-Virus ZIP Archive Processing Overflow |
13704 | F-Secure Multiple Products ARJ Archive Handling Overflow |
10963 | Multiple Anti-Virus Zero Compressed Size Header Detection Bypass |
6423 | F-Secure Anti-Virus Products LHA Archive Processing Overflow |
5755 | LHA Arbitrary File Access |
5753 | LHA get_header() Function File / Directory Name Handling Overflow |
ExploitDB Exploits
id | Description |
---|---|
24067 | LHA 1.x Buffer Overflow/Directory Traversal Vulnerabilities |
OpenVAS Exploits
id | Description |
---|---|
2008-09-24 | Name : Gentoo Security Advisory GLSA 200405-02 (lha) File : nvt/glsa_200405_02.nasl |
2008-09-04 | Name : FreeBSD Ports: lha File : nvt/freebsd_lha0.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 515-1 (lha) File : nvt/deb_515_1.nasl |
0000-00-00 | Name : Slackware Advisory SSA:2004-125-01 lha update in bin package File : nvt/esoft_slk_ssa_2004_125_01.nasl |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | F-Secure Anti-Virus LHA processing buffer overflow attempt RuleID : 15966 - Type : FILE-OTHER - Revision : 9 |
2014-01-10 | F-Secure AntiVirus library heap overflow attempt RuleID : 15583 - Type : FILE-OTHER - Revision : 10 |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2010-04-14 | Name: An antivirus application installed on the remote host is affected by a scan e... File: fsecure_fsc_2010_01.nasl - Type: ACT_GATHER_INFO |
2009-04-23 | Name: The remote FreeBSD host is missing a security-related update. File: freebsd_pkg_a2ffb6279c5311d893660020ed76ef5a.nasl - Type: ACT_GATHER_INFO |
2006-01-24 | Name: An antivirus application installed on the remote host is affected by multiple... File: fsecure_archive_overflows.nasl - Type: ACT_GATHER_INFO |
2005-07-13 | Name: The remote Slackware host is missing a security update. File: Slackware_SSA_2004-125-01.nasl - Type: ACT_GATHER_INFO |
2004-11-02 | Name: The remote Mandrake Linux host is missing a security update. File: mandrake_MDKSA-2004-118.nasl - Type: ACT_GATHER_INFO |
2004-09-29 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-515.nasl - Type: ACT_GATHER_INFO |
2004-08-30 | Name: The remote Gentoo host is missing one or more security-related patches. File: gentoo_GLSA-200405-02.nasl - Type: ACT_GATHER_INFO |
2004-07-23 | Name: The remote Fedora Core host is missing a security update. File: fedora_2004-119.nasl - Type: ACT_GATHER_INFO |
2004-07-06 | Name: The remote Red Hat host is missing a security update. File: redhat-RHSA-2004-178.nasl - Type: ACT_GATHER_INFO |