PT-2006-5003 · Cisco · Clamav

Damian Put

·

Published

2006-10-16

·

Updated

2024-06-15

·

CVE-2006-4182

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ClamAV versions 0.88.1 through 0.88.4 ClamAV versions prior to 0.88.5
Description The issue allows remote attackers to cause a denial of service and execute arbitrary code via a crafted Portable Executable file. This leads to a heap-based buffer overflow when less memory is allocated than expected.
Recommendations For ClamAV versions 0.88.1 through 0.88.4, update to version 0.88.5 or later. For ClamAV versions prior to 0.88.5, update to version 0.88.5 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4182
DSA-1196-1
OPENSUSE-SU-2024:10685-1

Affected Products

Clamav