CVE-2008-1412: Input Validation
Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, allows remote attackers to execute arbitrary code or cause a denial of service (hang or crash) via a malformed archive that triggers an unhandled exception, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1412?
CVE-2008-1412 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2008-1412?
To fix CVE-2008-1412, update affected F-Secure products to the latest available version that addresses this vulnerability.
What F-Secure products are affected by CVE-2008-1412?
CVE-2008-1412 affects multiple F-Secure products including Internet Security and Anti-Virus 2006 through 2008, among others.
What can attackers do with CVE-2008-1412?
Attackers can exploit CVE-2008-1412 to execute arbitrary code on the vulnerable system or cause it to hang or crash.
Is there any known exploit for CVE-2008-1412?
Yes, there are indications that CVE-2008-1412 can be exploited using specially crafted malformed archive files.