VDB
CVE-2008-3447
CVE-2008-3447
PUBLISHED
CVSS 5 MEDIUM
The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, probably related to invalid offsets.
EPSS 11.33% · 93.7th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
11.33%
93.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| f-prot | scanning_engine | 4.4.4.56 |
| n/a | n/a | n/a |
| f-prot | f-prot_antivirus | 6.2.1.4252 |
Timeline
- Jul 31, 2008 PoC Published
- Aug 4, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 20080731 F-PROT antivirus 6.2.1.4252 infinite loop denial of service via malformed archive mailing-list
- 1020612 vdb
- 6174 exploit
- ADV-2008-2283 vdb
- 31313 third-party-advisory
- fprotantivirus-infiniteloop-dos(44134) vdb
- 30461 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2008-3447 advisory