CVE Vulnerabilities

CVE-2008-6085

Published: Feb 06, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
F-secure_anti-virusF-secure7.02 (including)7.02 (including)
F-secure_anti-virusF-secure2006 (including)2006 (including)
F-secure_anti-virusF-secure2007 (including)2007 (including)
F-secure_anti-virusF-secure2008 (including)2008 (including)
F-secure_anti-virusF-secure2009 (including)2009 (including)
F-secure_anti-virus_for_citrix_serversF-secure*7.00 (including)
F-secure_anti-virus_for_microsoft_exchangeF-secure*7.10 (including)
F-secure_anti-virus_for_microsoft_exchangeF-secure6.62 (including)6.62 (including)
F-secure_anti-virus_for_microsoft_exchangeF-secure7.00 (including)7.00 (including)
F-secure_anti-virus_for_mimesweeperF-secure*5.61 (including)
F-secure_anti-virus_for_windows_serversF-secure*8.00 (including)
F-secure_anti-virus_for_workstationsF-secure7.10 (including)7.10 (including)
F-secure_anti-virus_for_workstationsF-secure7.11 (including)7.11 (including)
F-secure_anti-virus_linux_client_securityF-secure*5.54 (including)
F-secure_anti-virus_linux_client_securityF-secure5.30 (including)5.30 (including)
F-secure_anti-virus_linux_client_securityF-secure5.52 (including)5.52 (including)
F-secure_anti-virus_linux_client_securityF-secure5.53 (including)5.53 (including)
F-secure_anti-virus_linux_server_securityF-secure*5.54 (including)
F-secure_anti-virus_linux_server_securityF-secure5.30 (including)5.30 (including)
F-secure_anti-virus_linux_server_securityF-secure5.52 (including)5.52 (including)
F-secure_client_securityF-secure*7.12 (including)
F-secure_client_securityF-secure7.11 (including)7.11 (including)
F-secure_home_server_securityF-secure2009 (including)2009 (including)
F-secure_internet_gatekeeper_for_linuxF-secure*2.16 (including)
F-secure_internet_gatekeeper_for_windowsF-secure*6.61 (including)
F-secure_internet_securityF-secure7.02 (including)7.02 (including)
F-secure_internet_securityF-secure2006 (including)2006 (including)
F-secure_internet_securityF-secure2007 (including)2007 (including)
F-secure_internet_securityF-secure2008 (including)2008 (including)
F-secure_internet_securityF-secure2009 (including)2009 (including)
F-secure_linux_securityF-secure*7.01 (including)
F-secure_messaging_security_gatewayF-secure*5.0.4 (including)
F-secure_messaging_security_gatewayF-secure4.0.7 (including)4.0.7 (including)
F-secure_protection_service_for_businessF-secure*3.10 (including)
F-secure_protection_service_for_businessF-secure3.00 (including)3.00 (including)
F-secure_protection_service_for_consumersF-secure*8.00 (including)
F-secure_protection_service_for_consumersF-secure5.00 (including)5.00 (including)
F-secure_protection_service_for_consumersF-secure6.00 (including)6.00 (including)
F-secure_protection_service_for_consumersF-secure7.00 (including)7.00 (including)

References