查看: 3708|回复: 7
收起左侧

[资讯] F-Secure 安全公告 FSC-2008-3(2008-10-21)

[复制链接]
lzbbb
发表于 2008-10-21 20:26:01 | 显示全部楼层 |阅读模式
Date issued2008-10-21
Last updated2008-10-21
Risk levelCritical (Low/Medium/High/Critical)
Brief descriptionIf attackers send specially-made compressed file archives to users, whose antivirus software is set to scan inside compressed archives, this causes an integer overflow. The result is a controlled buffer overflow attack. It allows the attackers to control the computer on the system level.
Mitigating factors:
  • Attackers can exploit the vulnerability only if the antivirus software is set to scan inside compressed archives. In general, compressed archives are scanned during scheduled scans on servers and in gateway environments. In a typical configuration, on-access scanning does not scan inside compressed archives. Therefore, attackers cannot usually exploit the vulnerability in client environments.
  • Attackers can exploit the vulnerability by sending specially-made compressed file archives to users. At the time of publishing the Security Bulletin, there are no known exploits.

Affected platformsAll supported platforms
Clients
Products:F-Secure Internet Security 2008
F-Secure Internet Security 2007 Second Edition
F-Secure Internet Security 2007
F-Secure Internet Security 2006
F-Secure Anti-Virus 2008
F-Secure Anti-Virus 2007 Second Edition
F-Secure Anti-Virus 2007
F-Secure Anti-Virus 2006
F-Secure Client Security 7.12 and earlier
F-Secure Anti-Virus for Workstations 7.11 and earlier
F-Secure Linux Security 7.01 and earlier
F-Secure Anti-Virus Linux Client Security 5.54 and earlier
Solutions based on F-Secure Protection Service for Consumers version 8.00 and earlier
Solutions based on F-Secure Protection Service for Business version 3.10 and earlier
Risk level:High
Servers
Products:F-Secure Home Server Security 2009
F-Secure Anti-Virus for Windows Servers 8.00 and earlier
F-Secure Anti-Virus for Citrix Servers 7.00 and earlier
F-Secure Linux Security 7.01 and earlier
F-Secure Anti-Virus Linux Server Security 5.54 and earlier
F-Secure Anti-Virus for Linux Servers 4.65
Risk level:Critical
Gateways
Products:F-Secure Anti-Virus for Microsoft Exchange 7.10 and earlier
F-Secure Internet Gatekeeper for Windows 6.61 and earlier
F-Secure Internet Gatekeeper for Linux 2.16 and earlier
F-Secure Anti-Virus for Linux Gateways 4.65
F-Secure Anti-Virus for MIMEsweeper 5.61 and earlier
F-Secure Messaging Security Gateway 5.0.4 and earlier
Risk level:Critical
Bulletin locationhttp://www.f-secure.com/security/fsc-2008-3.shtml
Available patches:
F-Secure deliver patches to its supported product versions that are vulnerable. For further information on supported products and F-Secure’s Product Lifecycle Policy, please see:
http://www.f-secure.com/productmanagement/
ProductVersionsHotfix IDDownload
F-Secure Client Security7.12,
7.11
fsav744-03ftp://ftp.f-secure.com/support/hotfix/fsavcs/fsav744-03-signed.fsfix
F-Secure Anti-Virus for Workstations7.11
7.10
fsav744-03ftp://ftp.f-secure.com/support/hotfix/fsav/fsav744-03-signed.fsfix
F-Secure Anti-Virus for Windows Servers8.00 fsav830-01ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsav830-01-signed.fsfix
F-Secure Anti-Virus for Windows Servers7.01,
7.00
fsav722-01ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsav722-01-signed.fsfix
F-Secure Anti-Virus for Citrix Servers7.00fsav722-01ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsav722-01-signed.fsfix
F-Secure Anti-Virus for Citrix Servers5.52fsavsr552-16ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsavsr552-16-signed.fsfix
F-Secure Linux Security7.01New product version 7.02http://www.f-secure.com/webclub/fsls.html
F-Secure Linux Client Security5.54New product build #7410http://www.f-secure.com/webclub/fsls5.html
F-Secure Linux Server Security5.54New product build #7410http://www.f-secure.com/webclub/fsssl.html
F-Secure Anti-Virus for Linux Servers4.65New product build #7400http://www.f-secure.com/webclub/fsavsrvl.html
F-Secure Anti-Virus for Microsoft Exchange7.10fsavmse710-04ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fsavmse710-04.zip
F-Secure Anti-Virus for Microsoft Exchange7.00fsavmse700-03ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fsavmse700-03.zip
F-Secure Anti-Virus for Microsoft Exchange6.62fsavmse662-07ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fsavmse662-07.zip
F-Secure Internet Gatekeeper for Windows6.61fsigk661-03ftp://ftp.f-secure.com/support/hotfix/fsig/fsigk661-03.zip
F-Secure Internet Gatekeeper for Linux2.16New product build #580http://www.f-secure.com/webclub/fsigkl.html
F-Secure Anti-Virus for MIMEsweeper5.61fsavsr552-16ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsavsr552-16-signed.fsfix
F-Secure Anti-Virus for Linux Gateways4.65New product build #7400http://www.f-secure.com/webclub/fsavgwl.html
F-Secure Messaging Security Gateway5.0.4,
4.0.7
Packages will be available in the update channel, and installed automatically.
Protection Services For Consumers8, 7, 6, 5Packages will be available in the update channel, and installed automatically.
Protection Services For Businesses3.1Packages will be available in the update channel, and installed automatically.
F-Secure Internet Security2008,
2007
v.7.02,
2007,
2006
Packages will be available in the update channel, and installed automatically.
F-Secure Anti-Virus2008,
2007
v.7.02,
2007,
2006
Packages will be available in the update channel, and installed automatically.
F-Secure Home Server Security2009Packages will be available in the update channel, and installed automatically.
Credits:F-Secure want to thank Tamas Feher, 2F 2000 Kft., Hungary, for bringing this issue to our attention.
Revision history:FSC-2008-10-21
Contact information:
Support: http://support.f-secure.com/enu/home/contactus/
Security: http://www.f-secure.com/security/
URL: http://www.f-secure.com/
lzbbb
 楼主| 发表于 2008-10-21 20:31:43 | 显示全部楼层
风险等级:危急

描述:

如果攻击者发送特制的压缩文件存档给用户,其防病毒软件设置为扫描压缩文件内部,这会造成一个整体溢出。其结果是控制的缓冲区溢出攻击。它允许攻击者控制计算机系统。

受影响系统:见一楼,注意  F-Secure Client Security 7.12 及其早期版本需更新,F-Secure Internet Security 2008 及其早期版本需更新。
                                            F-Secure Client Security 8.00  及  F-Secure Internet Security 2009 不在需更新列表中。

[ 本帖最后由 lzbbb 于 2008-10-21 20:36 编辑 ]

评分

参与人数 1人气 +1 收起 理由
ballakay + 1 感谢提供分享

查看全部评分

kris
发表于 2008-10-21 20:40:45 | 显示全部楼层
谢谢L大
还好我用的工作站8.00版未在此列。
本拉稀
头像被屏蔽
发表于 2008-10-21 21:56:55 | 显示全部楼层
由此可见,使用V大和L大在10月15日发布的最新版本的FSCS的同学可以不用安装此次的重要补丁。
gho
发表于 2008-10-22 13:46:10 | 显示全部楼层
是啊CS 8.0不需要更新
aura
发表于 2008-10-22 16:21:26 | 显示全部楼层
这两天FS的日子不太好过呀
丢三落四
发表于 2008-10-23 00:03:25 | 显示全部楼层
嘿嘿,偶的版本不用更新。
yuna
发表于 2008-10-28 11:26:48 | 显示全部楼层
我的也是用8.0的了!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 11:10 , Processed in 0.128534 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表