First published: Fri Feb 06 2009(Updated: )
Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
f-secure f-secure anti-virus | =7.02 | |
f-secure f-secure anti-virus | =2006 | |
f-secure f-secure anti-virus | =2007 | |
f-secure f-secure anti-virus | =2007 | |
f-secure f-secure anti-virus | =2008 | |
f-secure f-secure anti-virus | =2009 | |
F-Secure Anti-Virus for Citrix servers | <=7.00 | |
F-Secure Anti-Virus for Microsoft Exchange | <=7.10 | |
F-Secure Anti-Virus for Microsoft Exchange | =6.62 | |
F-Secure Anti-Virus for Microsoft Exchange | =7.00 | |
F-Secure Anti-Virus for MIMEsweeper | <=5.61 | |
F-Secure Anti-Virus for Windows servers | <=8.00 | |
F-Secure Anti-Virus for workstations | =7.10 | |
F-Secure Anti-Virus for workstations | =7.11 | |
F-Secure Anti-Virus Linux Client Security | <=5.54 | |
F-Secure Anti-Virus Linux Client Security | =5.30 | |
F-Secure Anti-Virus Linux Client Security | =5.52 | |
F-Secure Anti-Virus Linux Client Security | =5.53 | |
F-Secure Anti-Virus Linux Server Security | <=5.54 | |
F-Secure Anti-Virus Linux Server Security | =5.30 | |
F-Secure Anti-Virus Linux Server Security | =5.52 | |
F-Secure Client Security | <=7.12 | |
F-Secure Client Security | =7.11 | |
F-Secure Home Server Security | =2009 | |
F-Secure Internet Gatekeeper for Linux | <=2.16 | |
F-Secure Internet GateKeeper for Windows | <=6.61 | |
f-secure f-secure internet security | =7.02 | |
f-secure f-secure internet security | =2006 | |
f-secure f-secure internet security | =2007 | |
f-secure f-secure internet security | =2007 | |
f-secure f-secure internet security | =2008 | |
f-secure f-secure internet security | =2009 | |
F-Secure Linux Security | <=7.01 | |
F-Secure Secure Messaging Secure Gateway | <=5.0.4 | |
F-Secure Secure Messaging Secure Gateway | =4.0.7 | |
F-Secure Protection Service for Business | <=3.10 | |
F-Secure Protection Service for Business | =3.00 | |
F-Secure protection service for consumers | <=8.00 | |
F-Secure protection service for consumers | =5.00 | |
F-Secure protection service for consumers | =6.00 | |
F-Secure protection service for consumers | =7.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6085 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2008-6085, update your F-Secure anti-virus products to the latest version provided by the vendor.
CVE-2008-6085 affects multiple F-Secure anti-virus products, including Internet Security and Anti-Virus versions from 2006 to 2008.
CVE-2008-6085 allows remote attackers to execute arbitrary code through vulnerable F-Secure anti-virus products by exploiting an integer overflow.
The risk of CVE-2008-6085 is increased when F-Secure products are configured to scan inside compressed archives.