First published: Tue Nov 20 2007(Updated: )
AhnLab Antivirus 3 Internet Security 2008 Platinum appends data to a filename string at a location indicated by the "Filename length" field in a ZIP header, which allows remote attackers to cause a denial of service (machine crash) and possibly execute arbitrary code via a ZIP file in which this field's value is larger than the actual number of bytes in the filename.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AhnLab V3 Internet Security | =2008 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-6060 is classified as high due to its potential to cause denial of service and arbitrary code execution.
To fix CVE-2007-6060, you should update AhnLab V3 Internet Security to the latest version that addresses this vulnerability.
CVE-2007-6060 enables remote attackers to cause a denial of service by manipulating ZIP files.
CVE-2007-6060 affects AhnLab V3 Internet Security 2008 Platinum.
Yes, CVE-2007-6060 can potentially allow remote attackers to execute arbitrary code.