Description
Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
Affected products
- F-Secure / f-secure_anti-virus4.65
- F-Secure / f-secure_anti-virus4.65
- F-Secure / f-secure_anti-virus5.42
- F-Secure / f-secure_anti-virus5.44
- F-Secure / f-secure_anti-virus5.52
- F-Secure / f-secure_anti-virus5.61
- F-Secure / f-secure_anti-virus6.40
- F-Secure / f-secure_anti-virus2005 – 2005
- F-Secure / f-secure_anti-virus2006 – 2006
- F-Secure / f-secure_anti-virus2007 – 2007
- F-Secure / f-secure_anti-virus_client_security6.03
- F-Secure / f-secure_anti-virus_linux_client_security5.30
- F-Secure / f-secure_anti-virus_linux_server_security5.30
- F-Secure / f-secure_internet_security2005 – 2005
- F-Secure / f-secure_internet_security2006 – 2006
- F-Secure / f-secure_internet_security2007 – 2007
- F-Secure / f-secure_protection_service6.40
- F-Secure / internet_gatekeeper2.16
- F-Secure / internet_gatekeeper6.60
References
- VENDOR_ADVISORYhttp://secunia.com/advisories/25426
- MISChttp://www.securitytracker.com/id?1018148
- MISChttp://securitytracker.com/id?1018147
- MISChttp://www.securitytracker.com/id?1018146
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2007/1985
- MISChttp://www.securityfocus.com/archive/1/470256/100/0/threaded
- MISChttp://www.f-secure.com/security/fsc-2007-1.shtml
- MISChttp://osvdb.org/36724
- MISChttp://www.securityfocus.com/bid/24235
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/34575
- MISChttp://www.nruns.com/security_advisory_fsecure_lzh.php