Vulnerability Name: | CVE-2006-2838 (CCN-26799) | ||||||||
Assigned: | 2006-06-01 | ||||||||
Published: | 2006-06-01 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | Buffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors. Note: By default, the connections are only allowed from the local host. Update to a fixed version or apply hotfix. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-2838 Source: CCN Type: SA20407 F-Secure Products Web Console Buffer Overflow Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 20407 Source: CCN Type: SECTRACK ID: 1016196 F-Secure Anti-Virus for Microsoft Exchange Buffer Overflow in Web Console May Let Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1016196 Source: CCN Type: SECTRACK ID: 1016197 F-Secure Internet Gatekeeper Buffer Overflow in Web Console May Let Remote Users Execute Arbitrary Code Source: SECTRACK Type: Patch 1016197 Source: CCN Type: F-Secure Security Bulletin FSC-2006-3 Buffer overflow in Web console of F-Secure Anti-Virus for Microsoft Exchange and F-Secure Internet Gatekeeper Source: CONFIRM Type: Patch http://www.f-secure.com/security/fsc-2006-3.shtml Source: CCN Type: OSVDB ID: 25937 F-Secure Multiple Products Web Console Pre-authentication Overflow Source: CCN Type: BID-18201 F-Secure Multiple Products Web Console Buffer Overflow Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-2076 Source: XF Type: UNKNOWN fsecure-webconsole-bo(26799) Source: XF Type: UNKNOWN fsecure-webconsole-bo(26799) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |