Lucene search

K
cve[email protected]CVE-2006-5645
HistoryNov 01, 2006 - 3:07 p.m.

CVE-2006-5645

2006-11-0115:07:00
CWE-399
web.nvd.nist.gov
20
cve-2006-5645
sophos
endpoint security
denial of service
rar
archive vulnerability

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.5 Medium

AI Score

Confidence

High

0.186 Low

EPSS

Percentile

96.2%

Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when “Enabled scanning of archives” is set, allows remote attackers to cause a denial of service (infinite loop) via a malformed RAR archive with an Archive Header section with the head_size and pack_size fields set to zero.

Affected configurations

NVD
Node
sophosanti-virusMatch4.04
OR
sophosanti-virusMatch4.05
OR
sophosanti-virusMatch4.5.3
OR
sophosanti-virusMatch4.5.4
OR
sophosanti-virusMatch4.5.11
OR
sophosanti-virusMatch4.5.12
OR
sophosanti-virusMatch4.7.1
OR
sophosanti-virusMatch4.7.2
OR
sophosanti-virusMatch5.0.1
OR
sophosanti-virusMatch5.0.2
OR
sophosanti-virusMatch5.0.4
OR
sophosanti-virusMatch5.1
OR
sophosanti-virusMatch5.2
OR
sophosanti-virusMatch5.2.1
OR
sophosanti-virusMatch6.0.4
OR
sophosendpoint_securityRange6.04

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.5 Medium

AI Score

Confidence

High

0.186 Low

EPSS

Percentile

96.2%

Related for CVE-2006-5645