HIGH
Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335
Published May 31, 2007
7.5
HIGHCVSS 2.0
EPSS 5.21%
Description
Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
Affected products
No data.
OR
- ≤ 4.65
- ≤ 4.65
- ≤ 5.42
- ≤ 5.44
- ≤ 5.52
- ≤ 5.61
- ≤ 6.40
- 2005
- 2006
- 2007
- ≤ 6.03
- ≤ 5.30
- ≤ 5.30
- 2005
- 2006
- 2007
- ≤ 6.40
- ≤ 2.16
- ≤ 6.60
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://osvdb.org/36724 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/25426 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://securitytracker.com/id?1018147 vdb-entryx_refsource_SECTRACK
- http://www.f-secure.com/security/fsc-2007-1.shtml x_refsource_CONFIRMPatchVendor Advisory
- http://www.nruns.com/security_advisory_fsecure_lzh.php x_refsource_MISC
- http://www.securityfocus.com/archive/1/470256/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/24235 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1018146 vdb-entryx_refsource_SECTRACK
- http://www.securitytracker.com/id?1018148 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2007/1985 vdb-entryx_refsource_VUPEN
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34575 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://osvdb.org/36724 | vdb-entryx_refsource_OSVDB | |
| http://secunia.com/advisories/25426 | third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory | |
| http://securitytracker.com/id?1018147 | vdb-entryx_refsource_SECTRACK | |
| http://www.f-secure.com/security/fsc-2007-1.shtml | x_refsource_CONFIRMPatchVendor Advisory | |
| http://www.nruns.com/security_advisory_fsecure_lzh.php | x_refsource_MISC | |
| http://www.securityfocus.com/archive/1/470256/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/24235 | vdb-entryx_refsource_BID | |
| http://www.securitytracker.com/id?1018146 | vdb-entryx_refsource_SECTRACK | |
| http://www.securitytracker.com/id?1018148 | vdb-entryx_refsource_SECTRACK | |
| http://www.vupen.com/english/advisories/2007/1985 | vdb-entryx_refsource_VUPEN | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/34575 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 31, 2007
Updated Aug 7, 2024
Reserved May 31, 2007
Link CVE-2007-2966
CISA Vulnrichment
Updated n/a