CVE-2004-2405

UnknownEPSS 1.72%

Last modified

CVE-2004-2405 is a vulnerability of currently unknown severity. Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote attackers to bypass scanning or cause a denial of service (crash or module restart), depending on the product, via a malformed LHA archive.. EPSS estimates a 1.72% chance of exploitation in the next 30 days.

Description

Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote attackers to bypass scanning or cause a denial of service (crash or module restart), depending on the product, via a malformed LHA archive.

Metrics

EPSS Probability
1.72%

74.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
F-SecureF-Secure Anti-Virus<= 4.52
F-SecureF-Secure Anti-Virus<= 5.42
F-SecureF-Secure Anti-Virus<= 5.52
F-SecureF-Secure Anti-Virus<= 6.21
F-SecureF-Secure Anti-Virus<= 2004
F-SecureF-Secure Anti-Virus4.60
F-SecureF-Secure For Firewalls<= 6.20
F-SecureF-Secure Internet Security<= 2004
F-SecureInternet Gatekeeper<= 6.32

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2004-2405?
Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote attackers to bypass scanning or cause a denial of service (crash or module restart), depending on the product, via a malformed LHA archive.
How severe is CVE-2004-2405?
Severity scoring for CVE-2004-2405 is pending analysis. The EPSS model estimates a 1.72% probability of exploitation in the next 30 days.
How do I fix CVE-2004-2405?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2004-2405?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST