CVE detail
CVE-2008-6085 — CVE-2008-6085
Published 2009-02-06 · Modified 2026-06-16 · Vendor f-secure · Product f-secure_anti-virus · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0554
EPSS probability
exploitation probability, 30d
92.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer overflow.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References