CVE-2007-2966

UnknownEPSS 5.21%

Last modified

CVE-2007-2966 is a vulnerability of currently unknown severity. Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.. EPSS estimates a 5.21% chance of exploitation in the next 30 days.

Description

Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.

Metrics

EPSS Probability
5.21%

91.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
F-SecureF-Secure Anti-Virus<= 4.65
F-SecureF-Secure Anti-Virus<= 5.42
F-SecureF-Secure Anti-Virus<= 5.44
F-SecureF-Secure Anti-Virus<= 5.52
F-SecureF-Secure Anti-Virus<= 5.61
F-SecureF-Secure Anti-Virus<= 6.40
F-SecureF-Secure Anti-Virus2005
F-SecureF-Secure Anti-Virus2006
F-SecureF-Secure Anti-Virus2007
F-SecureF-Secure Anti-Virus Client Security<= 6.03
F-SecureF-Secure Anti-Virus Linux Client Security<= 5.30
F-SecureF-Secure Anti-Virus Linux Server Security<= 5.30
F-SecureF-Secure Internet Security2005
F-SecureF-Secure Internet Security2006
F-SecureF-Secure Internet Security2007
F-SecureF-Secure Protection Service<= 6.40
F-SecureInternet Gatekeeper<= 2.16
F-SecureInternet Gatekeeper<= 6.60

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2007-2966?
Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
How severe is CVE-2007-2966?
Severity scoring for CVE-2007-2966 is pending analysis. The EPSS model estimates a 5.21% probability of exploitation in the next 30 days.
How do I fix CVE-2007-2966?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2007-2966?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST