what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

fsecure-format.txt

fsecure-format.txt
Posted Mar 20, 2007
Authored by Deral Heiland | Site layereddefense.com

A format string vulnerability was discovered within F-Secure Anti-Virus Client Security version 6.02. The vulnerability is due to improper processing of format strings when processing the Management Server name field.

tags | advisory, virus
SHA-256 | 7646621dbd70f86b3c91325b6ea6075097df767bc9d54eeb041687a2c3528983

fsecure-format.txt

Change Mirror Download
=================================================
Layered Defense Research Advisory 18 March 2007
=================================================
1) Affected Software
F-Secure Anti-Virus Client Security Version 6.02
=================================================
2) Severity Rating:
Low risk
Impact: Local read write arbitrary memory, denial of service.
=================================================
3) Description of Vulnerability
A format string vulnerability was discovered within F-Secure Anti-Virus Client Security Version 6.02. The vulnerability is due to improper processing of format strings when processing Management Server name field. When special crafted format strings are entered into the Management Server name field under Communication settings an attacker can read/write arbitrary memory and at a minimum can cause a denial of service condition.
=================================================
4) Solution
Fix: http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-cs-hotfixes.shtml
=================================================
5) Time Table:
11/20/2006 Reported Vulnerability to Vendor.
11/29/2007 Vendor acknowledged the vulnerability
03/01/2007 Vendor published hot fix
=================================================
6) Credits Discovered by Deral Heiland, www.LayeredDefense.com
=================================================
7) Reference
=================================================
8) About Layered Defense Layered Defense, Is a group of security professionals that work together on ethical Research, Testing and Training within the information security arena. http://www.layereddefense.com
=================================================
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    38 Files
  • 24
    Sep 24th
    65 Files
  • 25
    Sep 25th
    24 Files
  • 26
    Sep 26th
    26 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close