[Japanese]
|
JVNDB-2008-000050
|
Virus Security and Virus Security ZERO denial of service (DoS) vulnerability
|
Virus Security and Virus Security ZERO provided by SOURCENEXT CORPORATION contain a denial of service (DoS) vulnerability.
Virus Security and Virus Security ZERO are anti-virus software provided by SOURCENEXT CORPORATION. Virus Security and Virus Security ZERO contain a denial of service (DoS) vulnerability as they do not properly handle malicious compressed files when scanning.
Yuji Ukai of Fourteenforty Research Institute, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendor under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 4.3 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Partial
|
|
SOURCENEXT CORPORATION
- Virus Security version 9.5.0173 and earlier
- Virus Security ZERO version 9.5.0173 and earlier
|
|
The software may not function after scanning malicious compressed files.
|
[Update the Software]
Apply the latest updates provided by the vendor.
|
SOURCENEXT CORPORATION
|
- Improper Input Validation(CWE-20) [IPA Evaluation]
|
- CVE-2008-4429
|
- JVN : JVN#66077895
- National Vulnerability Database (NVD) : CVE-2008-4429
- IPA SECURITY ALERTS : Security Alert for Vulnerability in Virus Security and Virus Security ZERO
- JVN iPedia (Japanese) : JVNDB-2008-000050
|
- [2008/08/14]
Web page published
|