CVE-2006-0338

high

Description

Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data via malformed (1) RAR and (2) ZIP archives, which are not properly scanned.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/24199

http://www.vupen.com/english/advisories/2006/0257

http://www.securityfocus.com/bid/16309

http://www.osvdb.org/22633

http://www.f-secure.com/security/fsc-2006-1.shtml

http://www.ciac.org/ciac/bulletins/q-103.shtml

http://securitytracker.com/id?1015510

http://securitytracker.com/id?1015509

http://securitytracker.com/id?1015508

http://securitytracker.com/id?1015507

http://secunia.com/advisories/18529

Details

Source: Mitre, NVD

Published: 2006-01-21

Updated: 2017-07-20

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity: High