CVE-2021-40837

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/02/2022
Last modified:
11/02/2022

Description

A vulnerability affecting F-Secure antivirus engine before Capricorn update 2022-02-01_01 was discovered whereby decompression of ACE file causes the scanner service to stop. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f-secure:atlant:*:*:*:*:*:*:*:* 2022-02-01_01 (excluding)
cpe:2.3:a:f-secure:internet_gatekeeper:*:*:*:*:*:*:*:* 2022-02-01_01 (excluding)
cpe:2.3:a:f-secure:linux_security:*:*:*:*:*:*:*:* 2022-02-01_01 (excluding)
cpe:2.3:a:f-secure:security_cloud:*:*:*:*:*:*:*:* 2022-02-01_01 (excluding)
cpe:2.3:a:f-secure:elements_endpoint_detection_and_response:*:*:*:*:*:*:*:* 2022-02-01_01 (excluding)
cpe:2.3:a:f-secure:elements_endpoint_protection:*:*:*:*:*:*:*:* 2022-02-01_01 (excluding)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*