CVE-2007-2966
 
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
Un desbordamiento de búfer en el componente de descompresión LHA en productos antivirus de F-Secure para Microsoft Windows y Linux anterior a versión 20070529, permite a los atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (bloqueo de la aplicación) por medio de un archivo LHA ??creado, relacionado con un ajuste de entero, un problema similar a CVE-2006-4335.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-05-31 CVE Reserved
- 2007-05-31 CVE Published
- 2024-02-25 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://osvdb.org/36724 | Vdb Entry | |
http://securitytracker.com/id?1018147 | Vdb Entry | |
http://www.nruns.com/security_advisory_fsecure_lzh.php | X_refsource_misc | |
http://www.securityfocus.com/archive/1/470256/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/24235 | Vdb Entry | |
http://www.securitytracker.com/id?1018146 | Vdb Entry | |
http://www.securitytracker.com/id?1018148 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/1985 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34575 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/25426 | 2018-10-16 | |
http://www.f-secure.com/security/fsc-2007-1.shtml | 2018-10-16 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
F-secure Search vendor "F-secure" | F-secure Anti-virus Search vendor "F-secure" for product "F-secure Anti-virus" | <= 4.65 Search vendor "F-secure" for product "F-secure Anti-virus" and version " <= 4.65" | linux_gateways |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Anti-virus Search vendor "F-secure" for product "F-secure Anti-virus" | <= 4.65 Search vendor "F-secure" for product "F-secure Anti-virus" and version " <= 4.65" | linux_servers |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Anti-virus Search vendor "F-secure" for product "F-secure Anti-virus" | <= 5.42 Search vendor "F-secure" for product "F-secure Anti-virus" and version " <= 5.42" | windows_servers |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Anti-virus Search vendor "F-secure" for product "F-secure Anti-virus" | <= 5.44 Search vendor "F-secure" for product "F-secure Anti-virus" and version " <= 5.44" | workstations |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Anti-virus Search vendor "F-secure" for product "F-secure Anti-virus" | <= 5.52 Search vendor "F-secure" for product "F-secure Anti-virus" and version " <= 5.52" | citrix_servers |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Anti-virus Search vendor "F-secure" for product "F-secure Anti-virus" | <= 5.61 Search vendor "F-secure" for product "F-secure Anti-virus" and version " <= 5.61" | mimesweeper |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Anti-virus Search vendor "F-secure" for product "F-secure Anti-virus" | <= 6.40 Search vendor "F-secure" for product "F-secure Anti-virus" and version " <= 6.40" | ms_exchange |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Anti-virus Search vendor "F-secure" for product "F-secure Anti-virus" | 2005 Search vendor "F-secure" for product "F-secure Anti-virus" and version "2005" | - |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Anti-virus Search vendor "F-secure" for product "F-secure Anti-virus" | 2006 Search vendor "F-secure" for product "F-secure Anti-virus" and version "2006" | - |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Anti-virus Search vendor "F-secure" for product "F-secure Anti-virus" | 2007 Search vendor "F-secure" for product "F-secure Anti-virus" and version "2007" | - |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Anti-virus Client Security Search vendor "F-secure" for product "F-secure Anti-virus Client Security" | <= 6.03 Search vendor "F-secure" for product "F-secure Anti-virus Client Security" and version " <= 6.03" | - |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Anti-virus Linux Client Security Search vendor "F-secure" for product "F-secure Anti-virus Linux Client Security" | <= 5.30 Search vendor "F-secure" for product "F-secure Anti-virus Linux Client Security" and version " <= 5.30" | - |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Anti-virus Linux Server Security Search vendor "F-secure" for product "F-secure Anti-virus Linux Server Security" | <= 5.30 Search vendor "F-secure" for product "F-secure Anti-virus Linux Server Security" and version " <= 5.30" | - |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Internet Security Search vendor "F-secure" for product "F-secure Internet Security" | 2005 Search vendor "F-secure" for product "F-secure Internet Security" and version "2005" | - |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Internet Security Search vendor "F-secure" for product "F-secure Internet Security" | 2006 Search vendor "F-secure" for product "F-secure Internet Security" and version "2006" | - |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Internet Security Search vendor "F-secure" for product "F-secure Internet Security" | 2007 Search vendor "F-secure" for product "F-secure Internet Security" and version "2007" | - |
Affected
| ||||||
F-secure Search vendor "F-secure" | F-secure Protection Service Search vendor "F-secure" for product "F-secure Protection Service" | <= 6.40 Search vendor "F-secure" for product "F-secure Protection Service" and version " <= 6.40" | consumers |
Affected
| ||||||
F-secure Search vendor "F-secure" | Internet Gatekeeper Search vendor "F-secure" for product "Internet Gatekeeper" | <= 2.16 Search vendor "F-secure" for product "Internet Gatekeeper" and version " <= 2.16" | linux |
Affected
| ||||||
F-secure Search vendor "F-secure" | Internet Gatekeeper Search vendor "F-secure" for product "Internet Gatekeeper" | <= 6.60 Search vendor "F-secure" for product "Internet Gatekeeper" and version " <= 6.60" | - |
Affected
|