HIGH
Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files
Published Jan 10, 2006
7.5
HIGHCVSS 2.0
EPSS 10.09%
Description
Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files.
Affected products
No data.
OR
- .
- 0.51
- 0.52
- 0.53
- 0.54
- 0.60
- 0.65
- 0.67
- 0.68
- 0.68.1
- 0.70
- 0.75.1
- 0.80
- 0.80_rc1
- 0.80_rc2
- 0.80_rc3
- 0.80_rc4
- 0.81
- 0.82
- 0.83
- 0.84
- 0.84_rc1
- 0.84_rc2
- 0.85
- 0.85.1
- 0.86
- 0.86.1
- 0.86.2
- 0.87
- 0.87.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (20)
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041325.html mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/18379 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18453 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18463 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18478 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18548 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/342 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1015457 vdb-entryx_refsource_SECTRACK
- http://www.clamav.net/doc/0.88/ChangeLog x_refsource_CONFIRM
- http://www.debian.org/security/2006/dsa-947 vendor-advisoryx_refsource_DEBIAN
- http://www.gentoo.org/security/en/glsa/glsa-200601-07.xml vendor-advisoryx_refsource_GENTOO
- http://www.kb.cert.org/vuls/id/385908 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:016 vendor-advisoryx_refsource_MANDRIVA
- http://www.osvdb.org/22318 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/16191 vdb-entryx_refsource_BIDPatch
- http://www.trustix.org/errata/2006/0002/ vendor-advisoryx_refsource_TRUSTIX
- http://www.vupen.com/english/advisories/2006/0116 vdb-entryx_refsource_VUPEN
- http://www.zerodayinitiative.com/advisories/ZDI-06-001.html x_refsource_MISC
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-0170 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24047 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 10, 2006
Updated Aug 7, 2024
Reserved Jan 10, 2006
Link CVE-2006-0162
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-0170 Assigner mitre
Published Jan 10, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-0170