CVE-2006-0162: Buffer Overflow
Published Jan 10, 2006
·Updated
Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files.
Affected Software
30 affected components
Clam Anti-Virus clamav=.
Clam Anti-Virus clamav=0.51
Clam Anti-Virus clamav=0.52
Clam Anti-Virus clamav=0.53
Clam Anti-Virus clamav=0.54
Clam Anti-Virus clamav=0.60
Clam Anti-Virus clamav=0.65
Clam Anti-Virus clamav=0.67
Clam Anti-Virus clamav=0.68
Clam Anti-Virus clamav=0.68.1
Clam Anti-Virus clamav=0.70
Clam Anti-Virus clamav=0.75.1
Clam Anti-Virus clamav=0.80
Clam Anti-Virus clamav=0.80_rc1
Clam Anti-Virus clamav=0.80_rc2
Clam Anti-Virus clamav=0.80_rc3
Clam Anti-Virus clamav=0.80_rc4
Clam Anti-Virus clamav=0.81
Clam Anti-Virus clamav=0.82
Clam Anti-Virus clamav=0.83
Clam Anti-Virus clamav=0.84
Clam Anti-Virus clamav=0.84_rc1
Clam Anti-Virus clamav=0.84_rc2
Clam Anti-Virus clamav=0.85
Clam Anti-Virus clamav=0.85.1
Clam Anti-Virus clamav=0.86
Clam Anti-Virus clamav=0.86.1
Clam Anti-Virus clamav=0.86.2
Clam Anti-Virus clamav=0.87
Clam Anti-Virus clamav=0.87.1
Remediation
Patch Available
Patch Available
Event History
Jan 10, 2006
CVE Published
07:03 PM
Jan 11, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0162?
CVE-2006-0162 has a high severity rating due to its potential to cause denial of service and execute arbitrary code.
2
How do I fix CVE-2006-0162?
To fix CVE-2006-0162, you should upgrade ClamAV to version 0.88 or later.
3
What impact does CVE-2006-0162 have on ClamAV users?
CVE-2006-0162 can lead to crashes and exploitation of user systems through specially crafted UPX files.
4
Which versions of ClamAV are affected by CVE-2006-0162?
CVE-2006-0162 affects multiple versions of ClamAV including 0.80, 0.84, and many earlier releases.
5
Are there any workarounds for CVE-2006-0162?
Currently, the only effective workaround for CVE-2006-0162 is to upgrade to a patched version of ClamAV.