CVE-2008-0910
Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted RAR archive.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted RAR archive. NOTE: this might be related to CVE-2008-0792.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.52% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- f-secure/f-secure anti-virus · f-secure/f-secure anti-virus client security · f-secure/f-secure anti-virus for linux · f-secure/f-secure anti-virus for workstations · f-secure/f-secure anti-virus linux client security · f-secure/f-secure internet security · f-secure/f-secure protection service for business · f-secure/f-secure protection service for consumers
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/28919Vendor Advisory
- http://www.f-secure.com/security/fsc-2008-1.shtmlPatch
- http://www.securitytracker.com/id?1019405
- http://www.securitytracker.com/id?1019412
- http://www.securitytracker.com/id?1019413
- http://www.vupen.com/english/advisories/2008/0544/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40480
- http://secunia.com/advisories/28919Vendor Advisory
- http://www.f-secure.com/security/fsc-2008-1.shtmlPatch
- http://www.securitytracker.com/id?1019405
- http://www.securitytracker.com/id?1019412
- http://www.securitytracker.com/id?1019413
- http://www.vupen.com/english/advisories/2008/0544/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40480
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.