Description
The scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allows remote attackers to cause a denial of service (engine crash) via a CHM file with a large nb_dir value that triggers an out-of-bounds read.
Affected products
- f-prot / f-prot_antivirus3.11b – 3.11b
- f-prot / f-prot_antivirus3.12 – 3.12
- f-prot / f-prot_antivirus3.12a – 3.12a
- f-prot / f-prot_antivirus3.12b – 3.12b
- f-prot / f-prot_antivirus3.12c – 3.12c
- f-prot / f-prot_antivirus3.12d – 3.12d
- f-prot / f-prot_antivirus3.13 – 3.13
- f-prot / f-prot_antivirus3.13a – 3.13a
- f-prot / f-prot_antivirus3.14 – 3.14
- f-prot / f-prot_antivirus3.14a – 3.14a
- f-prot / f-prot_antivirus3.14b – 3.14b
- f-prot / f-prot_antivirus3.14c – 3.14c
- f-prot / f-prot_antivirus3.14d – 3.14d
- f-prot / f-prot_antivirus3.14e – 3.14e
- f-prot / f-prot_antivirus3.15 – 3.15
- f-prot / f-prot_antivirus3.15a – 3.15a
- f-prot / f-prot_antivirus3.15b – 3.15b
- f-prot / f-prot_antivirus3.16 – 3.16
- f-prot / f-prot_antivirus3.16a – 3.16a
- f-prot / f-prot_antivirus3.16b – 3.16b
- f-prot / f-prot_antivirus3.16c – 3.16c
- f-prot / f-prot_antivirus3.16d – 3.16d
- f-prot / f-prot_antivirus3.16e – 3.16e
- f-prot / f-prot_antivirus3.16f – 3.16f
- f-prot / f-prot_antivirus4.6.6 – 4.6.6
- f-prot / f-prot_antivirus6.0.5 – 6.0.5
- f-prot / f-prot_antivirus6.0.5.1 – 6.0.5.1
- f-prot / f-prot_antivirus6.0.6 – 6.0.6
- f-prot / f-prot_antivirus6.0.6.1 – 6.0.6.1
- f-prot / f-prot_antivirus6.0.6.3 – 6.0.6.3
- f-prot / f-prot_antivirus6.0.6.4 – 6.0.6.4
- f-prot / f-prot_antivirus6.0.7 – 6.0.7
- f-prot / f-prot_antivirus6.0.7.1 – 6.0.7.1
- f-prot / f-prot_antivirus6.0.8 – 6.0.8
- f-prot / scanning_engine4.3.2
References
- VENDOR_ADVISORYhttp://secunia.com/advisories/31118
- MISChttp://www.f-prot.com/download/ReleaseNotesWindows.txt
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2008/2124/references
- MISChttp://www.nruns.com/security_advisory_fprot_out-of-bound_memory_access_DoS.php
- MISChttp://www.securitytracker.com/id?1020507
- MISChttp://www.securityfocus.com/bid/30253
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/43835
Updated 49m ago · 2 sources