===================================================================== CERT-Renater Note d'Information No. 2008/VULN454 _____________________________________________________________________ DATE : 23/10/2008 HARDWARE PLATFORM(S) : / OPERATING SYSTEM(S) : Systems running F-Secure products. ====================================================================== http://www.f-secure.com/security/fsc-2008-3.shtml ______________________________________________________________________ Date issued 2008-10-21 Last updated 2008-10-21 Risk level Critical (Low/Medium/High/Critical) Brief description If attackers send specially-made compressed file archives to users, whose antivirus software is set to scan inside compressed archives, this causes an integer overflow. The result is a controlled buffer overflow attack. It allows the attackers to control the computer on the system level. Mitigating factors: * Attackers can exploit the vulnerability only if the antivirus software is set to scan inside compressed archives. In general, compressed archives are scanned during scheduled scans on servers and in gateway environments. In a typical configuration, on-access scanning does not scan inside compressed archives. Therefore, attackers cannot usually exploit the vulnerability in client environments. * Attackers can exploit the vulnerability by sending specially-made compressed file archives to users. At the time of publishing the Security Bulletin, there are no known exploits. Affected platforms All supported platforms Clients Products: F-Secure Internet Security 2008 F-Secure Internet Security 2007 Second Edition F-Secure Internet Security 2007 F-Secure Internet Security 2006 F-Secure Anti-Virus 2008 F-Secure Anti-Virus 2007 Second Edition F-Secure Anti-Virus 2007 F-Secure Anti-Virus 2006 F-Secure Client Security 7.12 and earlier F-Secure Anti-Virus for Workstations 7.11 and earlier F-Secure Linux Security 7.01 and earlier F-Secure Anti-Virus Linux Client Security 5.54 and earlier Solutions based on F-Secure Protection Service for Consumers version 8.00 and earlier Solutions based on F-Secure Protection Service for Business version 3.10 and earlier Risk level: High Servers Products: F-Secure Home Server Security 2009 F-Secure Anti-Virus for Windows Servers 8.00 and earlier F-Secure Anti-Virus for Citrix Servers 7.00 and earlier F-Secure Linux Security 7.01 and earlier F-Secure Anti-Virus Linux Server Security 5.54 and earlier F-Secure Anti-Virus for Linux Servers 4.65 Risk level: Critical Gateways Products: F-Secure Anti-Virus for Microsoft Exchange 7.10 and earlier F-Secure Internet Gatekeeper for Windows 6.61 and earlier F-Secure Internet Gatekeeper for Linux 2.16 and earlier F-Secure Anti-Virus for Linux Gateways 4.65 F-Secure Anti-Virus for MIMEsweeper 5.61 and earlier F-Secure Messaging Security Gateway 5.0.4 and earlier Risk level: Critical Bulletin location http://www.f-secure.com/security/fsc-2008-3.shtml Available patches: F-Secure deliver patches to its supported product versions that are vulnerable. For further information on supported products and F-Secure’s Product Lifecycle Policy, please see: http://www.f-secure.com/productmanagement/ ====================================================================== ========================================================= Les serveurs de référence du CERT-Renater http://www.urec.fr/securite http://www.cru.fr/securite http://www.renater.fr ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 151 bd de l'Hopital | fax : 01-53-94-20-41 + + 75013 Paris | email: certsvp@renater.fr + =========================================================