CVE-2008-6085

CWE-1893 documents3 sources
Severity
7.6HIGH
EPSS
10.5%
top 6.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 6
Latest updateMay 17

Description

Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer overflow.

CVSS vector

AV:N/AC:H/C:C/I:C/A:CExploitability: 4.9 | Impact: 10.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5f3f-vggf-74fg: Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, wh2022-05-17
CVEList
CVE-2008-6085: Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, wh2009-02-06
CVE-2008-6085 (HIGH CVSS 7.6) | Integer overflow in multiple F-Secu | cvebase.io