Title : F-Secure Antivirus Products ARJ archives Processing Vulnerability VUPEN ID : VUPEN/ADV-2005-0141 CVE ID : CVE-2005-0350 CWE ID : CWE-
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-02-10
Technical Description
A buffer overflow vulnerability was reported in several F-Secure antivirus products, and could be exploited by attackers or worms to compromise a system. This flaw resides in the F-Secure AntiVirus Library used to parse different file formats to detect malware. Before archive decompression, the library does not properly check the length of certain fields, which could be exploited to execute arbitrary code by sending an e-mail containing a crafted ARJ archive file.