CVE-2007-2967
Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.79%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.79% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- f-secure/f-secure anti-virus · f-secure/f-secure anti-virus client security · f-secure/f-secure anti-virus linux client security · f-secure/f-secure anti-virus linux server security · f-secure/f-secure internet security · f-secure/f-secure protection service · f-secure/internet gatekeeper
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063714.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063715.html
- http://osvdb.org/36725
- http://osvdb.org/36726
- http://secunia.com/advisories/25440Vendor Advisory
- http://securitytracker.com/id?1018147
- http://www.f-secure.com/security/fsc-2007-3.shtmlPatch, Vendor Advisory
- http://www.nruns.com/security_advisory_fsecure_arj.php
- http://www.nruns.com/security_advisory_fsecure_fsg.php
- http://www.securityfocus.com/archive/1/470462/100/0/threaded
- http://www.securityfocus.com/archive/1/470484/100/0/threaded
- http://www.securitytracker.com/id?1018146
- http://www.securitytracker.com/id?1018148
- http://www.vupen.com/english/advisories/2007/1985Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34581
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063714.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063715.html
- http://osvdb.org/36725
- http://osvdb.org/36726
- http://secunia.com/advisories/25440Vendor Advisory
- http://securitytracker.com/id?1018147
- http://www.f-secure.com/security/fsc-2007-3.shtmlPatch, Vendor Advisory
- http://www.nruns.com/security_advisory_fsecure_arj.php
- http://www.nruns.com/security_advisory_fsecure_fsg.php
- http://www.securityfocus.com/archive/1/470462/100/0/threaded
- http://www.securityfocus.com/archive/1/470484/100/0/threaded
- http://www.securitytracker.com/id?1018146
- http://www.securitytracker.com/id?1018148
- http://www.vupen.com/english/advisories/2007/1985Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34581
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.