CVE-2008-6085: Buffer Overflow
Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable scanning inside compressed archives (disable the 'scan inside compressed archives' option) in the configuration for each listed F-Secure product to avoid processing crafted RPM compressed archive files that can trigger the integer overflow and buffer overflow.
F-Secure Anti-Virus; F-Secure Anti-Virus Linux Client Security; F-Secure Anti-Virus Linux Server Security; F-Secure Anti-Virus for Citrix servers; F-Secure Anti-Virus for MIMEsweeper; F-Secure Anti-Virus for Microsoft Exchange; F-Secure Anti-Virus for Windows servers; F-Secure Anti-Virus for workstations; F-Secure Client Security; F-Secure Home Server Security; F-Secure Internet GateKeeper for Windows; F-Secure Internet Gatekeeper for Linux; F-Secure Internet Security 2010; F-Secure Linux Security; F-Secure Protection Service for Business; F-Secure Secure Messaging Secure Gateway; F-Secure protection service for consumers scan_inside_compressed_archives = false
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6085?
CVE-2008-6085 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2008-6085?
To fix CVE-2008-6085, update your F-Secure anti-virus products to the latest version provided by the vendor.
What products are affected by CVE-2008-6085?
CVE-2008-6085 affects multiple F-Secure anti-virus products, including Internet Security and Anti-Virus versions from 2006 to 2008.
What kind of attack does CVE-2008-6085 allow?
CVE-2008-6085 allows remote attackers to execute arbitrary code through vulnerable F-Secure anti-virus products by exploiting an integer overflow.
What configuration increases the risk of CVE-2008-6085?
The risk of CVE-2008-6085 is increased when F-Secure products are configured to scan inside compressed archives.