查看: 3378|回复: 7
收起左侧

[资讯] 2008.10.30 F-secure 对 FSC-2008-3 做了修正

[复制链接]
lzbbb
发表于 2008-10-30 23:15:27 | 显示全部楼层 |阅读模式
与 2008.10.21 的 FSC-2008-3 比较,补丁适用产品增加了 FSAV2009 与 FSIS2009。但 FSCS8.0 与 FSWKS8 确认不在补丁适用产品中,事实上,FSCS8.0 与 FSWKS8 是在 FSC-2008-3 补丁打包(2008.10.2)之后的2008.10.9日封装的,故 FSCS8.0 与 FSWKS8 封装的时候已经包含了该补丁。
先前本人发的两个相关帖子:

http://bbs.kafan.cn/thread-352307-1-1.html

http://bbs.kafan.cn/thread-353127-1-2.html


F-Secure 安全公告 FSC-2008-3(2008-10-21,2008-10-30官方更新)

Date issued2008-10-21
Last updated2008-10-30
Risk levelCritical (Low/Medium/High/Critical)
Brief descriptionIf attackers send specially-made compressed file archives to users, whose antivirus software is set to scan inside compressed archives, this causes an integer overflow. The result is a controlled buffer overflow attack. It allows the attackers to control the computer on the system level.
Mitigating factors:
  • Attackers can exploit the vulnerability only if the antivirus software is set to scan inside compressed archives. In general, compressed archives are scanned during scheduled scans on servers and in gateway environments. In a typical configuration, on-access scanning does not scan inside compressed archives. Therefore, attackers cannot usually exploit the vulnerability in client environments.
  • Attackers can exploit the vulnerability by sending specially-made compressed file archives to users. At the time of publishing the Security Bulletin, there are no known exploits.

Affected platformsAll supported platforms
Clients
Products:F-Secure Internet Security 2009
F-Secure Internet Security 2008
F-Secure Internet Security 2007 Second Edition
F-Secure Internet Security 2007
F-Secure Internet Security 2006
F-Secure Anti-Virus 2009
F-Secure Anti-Virus 2008
F-Secure Anti-Virus 2007 Second Edition
F-Secure Anti-Virus 2007
F-Secure Anti-Virus 2006
F-Secure Client Security 7.12 and earlier
F-Secure Anti-Virus for Workstations 7.11 and earlier
F-Secure Linux Security 7.01 and earlier
F-Secure Anti-Virus Linux Client Security 5.54 and earlier
Solutions based on F-Secure Protection Service for Consumers version 8.00 and earlier
Solutions based on F-Secure Protection Service for Business version 3.10 and earlier
Risk level:High
Servers
Products:F-Secure Home Server Security 2009
F-Secure Anti-Virus for Windows Servers 8.00 and earlier
F-Secure Anti-Virus for Citrix Servers 7.00 and earlier
F-Secure Linux Security 7.01 and earlier
F-Secure Anti-Virus Linux Server Security 5.54 and earlier
Risk level:Critical
Gateways
Products:F-Secure Anti-Virus for Microsoft Exchange 7.10 and earlier
F-Secure Internet Gatekeeper for Windows 6.61 and earlier
F-Secure Internet Gatekeeper for Linux 2.16 and earlier
F-Secure Anti-Virus for MIMEsweeper 5.61 and earlier
F-Secure Messaging Security Gateway 5.0.4 and earlier
Risk level:Critical
Bulletin locationhttp://www.f-secure.com/security/fsc-2008-3.shtml
Available patches:
F-Secure deliver patches to its supported product versions that are vulnerable. For further information on supported products and F-Secure’s Product Lifecycle Policy, please see:
http://www.f-secure.com/productmanagement/
ProductVersionsHotfix IDDownload
F-Secure Client Security7.12,
7.11
fsav744-03ftp://ftp.f-secure.com/support/hotfix/fsavcs/fsav744-03-signed.fsfix
F-Secure Anti-Virus for Workstations7.11
7.10
fsav744-03ftp://ftp.f-secure.com/support/hotfix/fsav/fsav744-03-signed.fsfix
F-Secure Anti-Virus for Windows Servers8.00 fsav830-01ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsav830-01-signed.fsfix
F-Secure Anti-Virus for Windows Servers7.01,
7.00
fsav722-02ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsav722-02-signed.fsfix
F-Secure Anti-Virus for Citrix Servers7.00fsav722-02ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsav722-02-signed.fsfix
F-Secure Anti-Virus for Citrix Servers5.52fsavsr552-16ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsavsr552-16-signed.fsfix
F-Secure Linux Security7.01New product version 7.02http://www.f-secure.com/webclub/fsls.html
F-Secure Linux Client Security5.54New product build #7410http://www.f-secure.com/webclub/fsls5.html
F-Secure Linux Server Security5.54New product build #7410http://www.f-secure.com/webclub/fsssl.html
F-Secure Anti-Virus for Microsoft Exchange7.10fsavmse710-04ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fsavmse710-04.zip
F-Secure Anti-Virus for Microsoft Exchange7.00fsavmse700-03ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fsavmse700-03.zip
F-Secure Anti-Virus for Microsoft Exchange6.62fsavmse662-07ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fsavmse662-07.zip
F-Secure Internet Gatekeeper for Windows6.61fsigk661-03ftp://ftp.f-secure.com/support/hotfix/fsig/fsigk661-03.zip
F-Secure Internet Gatekeeper for Linux2.16New product build #580http://www.f-secure.com/webclub/fsigkl.html
F-Secure Anti-Virus for MIMEsweeper5.61fsavsr552-16ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsavsr552-16-signed.fsfix
F-Secure Messaging Security Gateway5.0.4,
4.0.7
Packages will be available in the update channel, and installed automatically.
Protection Services For Consumers8, 7, 6, 5Packages will be available in the update channel, and installed automatically.
Protection Services For Businesses3.1Packages will be available in the update channel, and installed automatically.
F-Secure Internet Security2009,
2008,
2007
v.7.02,
2007,
2006
Packages will be available in the update channel, and installed automatically.
F-Secure Anti-Virus2009,
2008,
2007
v.7.02,
2007,
2006
Packages will be available in the update channel, and installed automatically.
F-Secure Home Server Security2009Packages will be available in the update channel, and installed automatically.
Credits:F-Secure want to thank Tamas Feher, 2F 2000 Kft., Hungary, for bringing this issue to our attention.
Revision history:FSC-2008-10-30
Contact information:
Support: http://support.f-secure.com/enu/home/contactus/
Security: http://www.f-secure.com/security/
URL: http://www.f-secure.com/

[ 本帖最后由 lzbbb 于 2008-10-30 23:21 编辑 ]
丢三落四
发表于 2008-10-30 23:20:28 | 显示全部楼层
嘿嘿,顶,L大,偶终于占个沙发了。
harrytien
发表于 2008-10-31 12:58:27 | 显示全部楼层
FS动作好慢,不过终于解决了
gho
发表于 2008-10-31 17:03:48 | 显示全部楼层
呵呵不用集成就好
wangmu_1985
发表于 2008-11-1 17:21:42 | 显示全部楼层
喜欢FS,给老爹的机子装了,但愿以后不要再中毒
lixiangby
发表于 2008-11-1 22:28:34 | 显示全部楼层
补丁装了的确让人感觉放心不少,不过目前对于fs的慢反应还是非常不满地……
ledled
发表于 2008-11-2 07:27:17 | 显示全部楼层
是通过自动更新获取还是手动下载
gho
发表于 2008-11-2 09:49:33 | 显示全部楼层

回复 7楼 ledled 的帖子

应该是手动下载
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 10:46 , Processed in 0.130236 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表