← Vulnerability feed

Vulnerability record · CVE-2007-2967 · published 31 May 2007

CVE-2007-2967: F-secure anti-virus improper input validation vulnerability

F Secure · F Secure Anti Virus

Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.

10.0 CVSS 2.0 High EPSS 4.8% · top 8.4% CWE-20 · Improper input validation
10.0CVSS 2.0 base score
4.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
30References
16 Jun 2026Last modified by NVD

Description

Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063714.html
http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063715.html
http://osvdb.org/36725
http://osvdb.org/36726
http://secunia.com/advisories/25440 Vendor Advisory
http://securitytracker.com/id?1018147
http://www.f-secure.com/security/fsc-2007-3.shtml PatchVendor Advisory
http://www.nruns.com/security_advisory_fsecure_arj.php
http://www.nruns.com/security_advisory_fsecure_fsg.php
http://www.securityfocus.com/archive/1/470462/100/0/threaded
http://www.securityfocus.com/archive/1/470484/100/0/threaded
http://www.securitytracker.com/id?1018146
http://www.securitytracker.com/id?1018148
http://www.vupen.com/english/advisories/2007/1985 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/34581
http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063714.html
http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063715.html
http://osvdb.org/36725
http://osvdb.org/36726
http://secunia.com/advisories/25440 Vendor Advisory
http://securitytracker.com/id?1018147
http://www.f-secure.com/security/fsc-2007-3.shtml PatchVendor Advisory
http://www.nruns.com/security_advisory_fsecure_arj.php
http://www.nruns.com/security_advisory_fsecure_fsg.php
http://www.securityfocus.com/archive/1/470462/100/0/threaded
http://www.securityfocus.com/archive/1/470484/100/0/threaded
http://www.securitytracker.com/id?1018146
http://www.securitytracker.com/id?1018148
http://www.vupen.com/english/advisories/2007/1985 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/34581

Track CVE-2007-2967 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-6409F-secure anti-virus vulnerabilityF-Secure Anti-Virus for Linux Gateways 4.65 allows remote attackers to cause a denial of service (possibly fatal scan error), and possibly bypass vir…EPSS 3.7%10.0CVE-2004-0234Clearswift mailsweeper memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow…EPSS 10%9.3CVE-2007-3300F-secure anti-virus vulnerabilityMultiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header …EPSS 3.7%7.6CVE-2008-6085F-secure anti-virus vulnerabilityInteger overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, w…EPSS 5.5%7.6CVE-2006-2838F-secure anti-virus vulnerabilityBuffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remo…EPSS 5.7%7.5CVE-2008-0910F-secure anti-virus permissions and access controls vulnerabilityMultiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and …EPSS 2.5%7.5CVE-2007-2966F-secure anti-virus memory buffer overflow vulnerabilityBuffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote atta…EPSS 5.2%7.5CVE-2006-0337F-secure anti-virus vulnerabilityBuffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlie…EPSS 5.8%

Source: NIST National Vulnerability Database (record CVE-2007-2967), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.