Multiple unspecified vulnerabilities in the scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allow remote attackers to cause a denial of service via (1) a crafted UPX-compressed file, which triggers an engine crash; (2) a crafted Microsoft Office file, which triggers an infinite loop; or (3) an ASPack-compressed file, which triggers an engine crash.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://secunia.com/advisories/31118 | patch vendor advisory third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43870 | vdb entry |
http://www.f-prot.com/download/ReleaseNotesWindows.txt | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43869 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43868 | vdb entry |
http://www.securityfocus.com/bid/30258 | vdb entry |