7.5 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
7.7 High
AI Score
Confidence
Low
0.875 High
EPSS
Percentile
98.7%
Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to execute arbitrary code via a crafted UPX packed file containing sections with large rsize values.
kolab.org/security/kolab-vendor-notice-10.txt
secunia.com/advisories/21368
secunia.com/advisories/21374
secunia.com/advisories/21433
secunia.com/advisories/21443
secunia.com/advisories/21457
secunia.com/advisories/21497
secunia.com/advisories/21562
security.gentoo.org/glsa/glsa-200608-13.xml
securitytracker.com/id?1016645
www.clamav.net/security/0.88.4.html
www.debian.org/security/2006/dsa-1153
www.mandriva.com/security/advisories?name=MDKSA-2006:138
www.novell.com/linux/security/advisories/2006_46_clamav.html
www.overflow.pl/adv/clamav_upx_heap.txt
www.securityfocus.com/archive/1/442681/100/0/threaded
www.securityfocus.com/bid/19381
www.trustix.org/errata/2006/0046/
www.vupen.com/english/advisories/2006/3175
www.vupen.com/english/advisories/2006/3275
exchange.xforce.ibmcloud.com/vulnerabilities/28286