MEDIUM
Integer overflow in the cli_scanpe function in the PE header parser (libclamav/pe.c) in Clam AntiVirus (ClamAV) before 0.88.1, when ArchiveMaxFileSize is disabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code
Published Apr 6, 2006
5.1
MEDIUMCVSS 2.0
EPSS 7.81%
Description
Integer overflow in the cli_scanpe function in the PE header parser (libclamav/pe.c) in Clam AntiVirus (ClamAV) before 0.88.1, when ArchiveMaxFileSize is disabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
Affected products
No data.
OR
- 0.51
- 0.52
- 0.53
- 0.54
- 0.60
- 0.65
- 0.67
- 0.68
- 0.68.1
- 0.70
- 0.75.1
- 0.80
- 0.80_rc1
- 0.80_rc2
- 0.80_rc3
- 0.80_rc4
- 0.81
- 0.82
- 0.83
- 0.84
- 0.84_rc1
- 0.84_rc2
- 0.85
- 0.85.1
- 0.86
- 0.86.1
- 0.86.2
- 0.87
- 0.87.1
- 0.88
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (27)
- http://lists.apple.com/archives/security-announce/2006/May/msg00003.html vendor-advisoryx_refsource_APPLE
- http://lists.suse.com/archive/suse-security-announce/2006-Apr/0002.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/19534 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19536 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19564 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19567 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19570 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19608 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/20077 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23719 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1015887 vdb-entryx_refsource_SECTRACK
- http://sourceforge.net/project/shownotes.php?release_id=407078&group_id=86638 x_refsource_CONFIRMPatch
- http://up2date.astaro.com/2006/05/low_up2date_6202.html x_refsource_CONFIRM
- http://www.debian.org/security/2006/dsa-1024 vendor-advisoryx_refsource_DEBIANPatchVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200604-06.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:067 vendor-advisoryx_refsource_MANDRIVA
- http://www.osvdb.org/24457 vdb-entryx_refsource_OSVDB
- http://www.overflow.pl/adv/clamavupxinteger.txt x_refsource_MISCExploitVendor Advisory
- http://www.securityfocus.com/archive/1/430405/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/17388 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/17951 vdb-entryx_refsource_BID
- http://www.trustix.org/errata/2006/0020 vendor-advisoryx_refsource_TRUSTIX
- http://www.us-cert.gov/cas/techalerts/TA06-132A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2006/1258 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/1779 vdb-entryx_refsource_VUPEN
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-1615 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25660 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 6, 2006
Updated Aug 7, 2024
Reserved Apr 5, 2006
Link CVE-2006-1614
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-1615 Assigner mitre
Published Apr 6, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-1615