Lucene search

K
cve[email protected]CVE-2006-4018
HistoryAug 08, 2006 - 8:04 p.m.

CVE-2006-4018

2006-08-0820:04:00
CWE-119
web.nvd.nist.gov
109
cve-2006-4018
buffer overflow
clam antivirus
clamav
upx
remote code execution
security vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.875 High

EPSS

Percentile

98.7%

Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to execute arbitrary code via a crafted UPX packed file containing sections with large rsize values.

Affected configurations

NVD
Node
clamavclamavMatch0.81
OR
clamavclamavMatch0.81rc1
OR
clamavclamavMatch0.82
OR
clamavclamavMatch0.83
OR
clamavclamavMatch0.84
OR
clamavclamavMatch0.84rc1
OR
clamavclamavMatch0.84rc2
OR
clamavclamavMatch0.85
OR
clamavclamavMatch0.85.1
OR
clamavclamavMatch0.86
OR
clamavclamavMatch0.86rc1
OR
clamavclamavMatch0.86.1
OR
clamavclamavMatch0.86.2
OR
clamavclamavMatch0.87
OR
clamavclamavMatch0.87.1
OR
clamavclamavMatch0.88
OR
clamavclamavMatch0.88.1
OR
clamavclamavMatch0.88.2
OR
clamavclamavMatch0.88.3

References

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.875 High

EPSS

Percentile

98.7%