CVE-2008-3243: Input Validation
Multiple unspecified vulnerabilities in the scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allow remote attackers to cause a denial of service via (1) a crafted UPX-compressed file, which triggers an engine crash; (2) a crafted Microsoft Office file, which triggers an infinite loop; or (3) an ASPack-compressed file, which triggers an engine crash.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3243?
CVE-2008-3243 has a medium severity as it can lead to denial of service.
How do I fix CVE-2008-3243?
To fix CVE-2008-3243, you should update F-Prot Antivirus to version 6.0.9.0 or later.
What software versions are affected by CVE-2008-3243?
CVE-2008-3243 affects multiple versions of F-Prot Antivirus prior to 6.0.9.0.
What types of files can trigger the vulnerabilities in CVE-2008-3243?
CVE-2008-3243 can be triggered by crafted UPX-compressed files and Microsoft Office files.
Is there a workaround for CVE-2008-3243?
The recommended action for CVE-2008-3243 is to update to the latest version of F-Prot Antivirus, as there are no known effective workarounds.