ID

VAR-200705-0115


CVE

CVE-2007-2965


TITLE

plural F-Secure Product Real-time Scanning Vulnerability gained privileges in components

Trust: 0.8

sources: JVNDB: JVNDB-2007-002111

DESCRIPTION

Unspecified vulnerability in the Real-time Scanning component in multiple F-Secure products, including Internet Security 2005, 2006 and 2007; Anti-Virus 2005, 2006 and 2007; and Solutions based on F-Secure Protection Service for Consumers 6.40 and earlier allows local users to gain privileges via a crafted I/O request packet (IRP), related to IOCTL (Input/Output Control) and "access validation of the address space.". Internet Gatekeeper is prone to a local security vulnerability. Local users can gain privileges with the help of a specially crafted I/O request packet (IRP)

Trust: 1.98

sources: NVD: CVE-2007-2965 // JVNDB: JVNDB-2007-002111 // BID: 86107 // VULHUB: VHN-26327

AFFECTED PRODUCTS

vendor:f securemodel:f-secure internet securityscope:eqversion:2006

Trust: 2.7

vendor:f securemodel:f-secure internet securityscope:eqversion:2005

Trust: 2.7

vendor:f securemodel:f-secure anti-virusscope:eqversion:2006

Trust: 2.7

vendor:f securemodel:f-secure anti-virusscope:eqversion:2005

Trust: 2.7

vendor:f securemodel:f-secure internet securityscope:eqversion:2007

Trust: 1.9

vendor:f securemodel:f-secure anti-virusscope:eqversion:2007

Trust: 1.9

vendor:f securemodel:f-secure anti-virusscope:lteversion:5.42

Trust: 1.0

vendor:f securemodel:f-secure anti-virusscope:lteversion:5.61

Trust: 1.0

vendor:f securemodel:f-secure anti-virusscope:lteversion:4.65

Trust: 1.0

vendor:f securemodel:internet gatekeeperscope:lteversion:6.60

Trust: 1.0

vendor:f securemodel:f-secure anti-virusscope:lteversion:5.44

Trust: 1.0

vendor:f securemodel:f-secure anti-virusscope:lteversion:6.40

Trust: 1.0

vendor:f securemodel:f-secure anti-virus linux client securityscope:lteversion:5.30

Trust: 1.0

vendor:f securemodel:f-secure anti-virus client securityscope:lteversion:6.03

Trust: 1.0

vendor:f securemodel:internet gatekeeperscope:lteversion:2.16

Trust: 1.0

vendor:f securemodel:f-secure protection servicescope:lteversion:6.40

Trust: 1.0

vendor:f securemodel:f-secure anti-virus linux server securityscope:lteversion:5.30

Trust: 1.0

vendor:f securemodel:f-secure anti-virusscope:lteversion:5.52

Trust: 1.0

vendor:f securemodel:f-secure anti-virusscope:eqversion:and 2007

Trust: 0.8

vendor:f securemodel:f-secure internet securityscope:eqversion:and 2007

Trust: 0.8

vendor:f securemodel:f-secure protection servicescope:lteversion:consumers 6.40

Trust: 0.8

vendor:f securemodel:f-secure anti-virusscope:eqversion:4.65

Trust: 0.6

vendor:f securemodel:f-secure anti-virusscope:eqversion:5.42

Trust: 0.6

vendor:f securemodel:f-secure anti-virusscope:eqversion:5.44

Trust: 0.6

vendor:f securemodel:internet gatekeeperscope:eqversion:6.60

Trust: 0.3

vendor:f securemodel:internet gatekeeper linuxscope:eqversion:2.16

Trust: 0.3

vendor:f securemodel:f-secure protection service consumersscope:eqversion:6.40

Trust: 0.3

vendor:f securemodel:f-secure anti-virus linux server securityscope:eqversion:5.30

Trust: 0.3

vendor:f securemodel:f-secure anti-virus linux client securityscope:eqversion:5.30

Trust: 0.3

vendor:f securemodel:f-secure anti-virus client securityscope:eqversion:6.03

Trust: 0.3

vendor:f securemodel:f-secure anti-virus ms exchangescope:eqversion:6.40

Trust: 0.3

vendor:f securemodel:f-secure anti-virus mimesweeperscope:eqversion:5.61

Trust: 0.3

vendor:f securemodel:f-secure anti-virus citrix serversscope:eqversion:5.52

Trust: 0.3

vendor:f securemodel:f-secure anti-virus workstationsscope:eqversion:5.44

Trust: 0.3

vendor:f securemodel:f-secure anti-virus windows serversscope:eqversion:5.42

Trust: 0.3

vendor:f securemodel:f-secure anti-virus linux serversscope:eqversion:4.65

Trust: 0.3

vendor:f securemodel:f-secure anti-virus linux gatewaysscope:eqversion:4.65

Trust: 0.3

sources: BID: 86107 // JVNDB: JVNDB-2007-002111 // CNNVD: CNNVD-200705-586 // NVD: CVE-2007-2965

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-2965
value: HIGH

Trust: 1.0

NVD: CVE-2007-2965
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200705-586
value: HIGH

Trust: 0.6

VULHUB: VHN-26327
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2007-2965
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-26327
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-26327 // JVNDB: JVNDB-2007-002111 // CNNVD: CNNVD-200705-586 // NVD: CVE-2007-2965

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2007-2965

THREAT TYPE

local

Trust: 0.9

sources: BID: 86107 // CNNVD: CNNVD-200705-586

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200705-586

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-002111

PATCH

title:Security advisoriesurl:http://www.f-secure.com/en/web/labs_global/security-advisories

Trust: 0.8

sources: JVNDB: JVNDB-2007-002111

EXTERNAL IDS

db:NVDid:CVE-2007-2965

Trust: 2.8

db:SECTRACKid:1018148

Trust: 2.0

db:SECTRACKid:1018146

Trust: 2.0

db:SECUNIAid:25439

Trust: 1.7

db:VUPENid:ADV-2007-1985

Trust: 1.7

db:OSVDBid:36727

Trust: 1.1

db:XFid:34579

Trust: 0.9

db:JVNDBid:JVNDB-2007-002111

Trust: 0.8

db:CNNVDid:CNNVD-200705-586

Trust: 0.7

db:BIDid:86107

Trust: 0.4

db:VULHUBid:VHN-26327

Trust: 0.1

sources: VULHUB: VHN-26327 // BID: 86107 // JVNDB: JVNDB-2007-002111 // CNNVD: CNNVD-200705-586 // NVD: CVE-2007-2965

REFERENCES

url:http://www.f-secure.com/security/fsc-2007-2.shtml

Trust: 2.0

url:http://www.securitytracker.com/id?1018146

Trust: 2.0

url:http://www.securitytracker.com/id?1018148

Trust: 2.0

url:http://secunia.com/advisories/25439

Trust: 1.7

url:http://osvdb.org/36727

Trust: 1.1

url:http://www.vupen.com/english/advisories/2007/1985

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/34579

Trust: 1.1

url:http://xforce.iss.net/xforce/xfdb/34579

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-2965

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-2965

Trust: 0.8

url:http://www.frsirt.com/english/advisories/2007/1985

Trust: 0.6

sources: VULHUB: VHN-26327 // BID: 86107 // JVNDB: JVNDB-2007-002111 // CNNVD: CNNVD-200705-586 // NVD: CVE-2007-2965

CREDITS

Unknown

Trust: 0.3

sources: BID: 86107

SOURCES

db:VULHUBid:VHN-26327
db:BIDid:86107
db:JVNDBid:JVNDB-2007-002111
db:CNNVDid:CNNVD-200705-586
db:NVDid:CVE-2007-2965

LAST UPDATE DATE

2024-11-23T22:43:23.407000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-26327date:2017-07-29T00:00:00
db:BIDid:86107date:2007-05-31T00:00:00
db:JVNDBid:JVNDB-2007-002111date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200705-586date:2007-06-01T00:00:00
db:NVDid:CVE-2007-2965date:2024-11-21T00:32:04.720

SOURCES RELEASE DATE

db:VULHUBid:VHN-26327date:2007-05-31T00:00:00
db:BIDid:86107date:2007-05-31T00:00:00
db:JVNDBid:JVNDB-2007-002111date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200705-586date:2007-05-31T00:00:00
db:NVDid:CVE-2007-2965date:2007-05-31T23:30:00