|
F-Secure Anti-Virus LHA Processing Buffer Overflow Vulnerability
Multiple F-Secure Anti-Virus applications are prone to a buffer-overflow vulnerability when they process certain LHA archive files. This issue occurs because the applications fail to properly check boundaries on user-supplied data before copying it to an insufficiently sized memory buffer. Successful exploits can allow attackers to execute arbitrary code with the privileges of the vulnerable application. Failed exploit attempts will likely result in denial-of-service conditions. Reports indicate that this vulnerability also occurs when processing malformed LZH archives, ARJ files, and FSG packed files. |
|
|
Privacy Statement |