Vulnerability Intelligence Report
CVE-2008-6085
Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer overflow.
No Active Exploit Signals
CVSS Base Score
7.6
HIGH
EPSS Probability:5.54%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| f-secure | f-secure_anti-virus | 7.02, 2006, 2007, 2008, 2009 |
| f-secure | f-secure_anti-virus_for_citrix_servers | all |
| f-secure | f-secure_anti-virus_for_microsoft_exchange | 6.62, 7.00 |
| f-secure | f-secure_anti-virus_for_mimesweeper | all |
| f-secure | f-secure_anti-virus_for_windows_servers | all |
| f-secure | f-secure_anti-virus_for_workstations | 7.10, 7.11 |
| f-secure | f-secure_anti-virus_linux_client_security | 5.30, 5.52, 5.53 |
| f-secure | f-secure_anti-virus_linux_server_security | 5.30, 5.52 |
| f-secure | f-secure_client_security | 7.11 |
| f-secure | f-secure_home_server_security | 2009 |
| f-secure | f-secure_internet_gatekeeper_for_linux | all |
| f-secure | f-secure_internet_gatekeeper_for_windows | all |
| f-secure | f-secure_internet_security | 7.02, 2006, 2007, 2008, 2009 |
| f-secure | f-secure_linux_security | all |
| f-secure | f-secure_messaging_security_gateway | 4.0.7 |
| f-secure | f-secure_protection_service_for_business | 3.00 |
| f-secure | f-secure_protection_service_for_consumers | 5.00, 6.00, 7.00 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
5.535%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2009-02-05T00:00:00 |
| Published | 2009-02-06T11:00:00 |
| Patch Date | 2008-10-21 |
| Last Updated | 2024-08-07T11:20:25 |
Community Chatter & Buzz