Lucene search

K
cve[email protected]CVE-2006-6458
HistoryDec 11, 2006 - 5:28 p.m.

CVE-2006-6458

2006-12-1117:28:00
web.nvd.nist.gov
21
trend micro
scan engine
denial of service
rar archive
nvd
vulnerability
cve-2006-6458

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

7 High

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.3%

The Trend Micro scan engine before 8.320 for Windows and before 8.150 on HP-UX and AIX, as used in Trend Micro PC Cillin - Internet Security 2006, Office Scan 7.3, and Server Protect 5.58, allows remote attackers to cause a denial of service (CPU consumption and system hang) via a malformed RAR archive with an Archive Header section with the head_size and pack_size fields set to zero, which triggers an infinite loop.

Affected configurations

NVD
Node
trend_microofficescanMatch7.3
OR
trend_micropc_cillin_-_internet_security_2006
OR
trend_microserverprotectMatch5.58emc

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

7 High

AI Score

Confidence

High

0.014 Low

EPSS

Percentile

86.3%

Related for CVE-2006-6458