First published: Thu Apr 06 2006(Updated: )
Integer overflow in the cli_scanpe function in the PE header parser (libclamav/pe.c) in Clam AntiVirus (ClamAV) before 0.88.1, when ArchiveMaxFileSize is disabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamXAV | =0.84 | |
ClamXAV | =0.80 | |
ClamXAV | =0.84_rc1 | |
ClamXAV | =0.80_rc3 | |
ClamXAV | =0.80_rc4 | |
ClamXAV | =0.65 | |
ClamXAV | =0.68 | |
ClamXAV | =0.86.1 | |
ClamXAV | =0.82 | |
ClamXAV | =0.85.1 | |
ClamXAV | =0.87 | |
ClamXAV | =0.85 | |
ClamXAV | =0.80_rc1 | |
ClamXAV | =0.75.1 | |
ClamXAV | =0.86.2 | |
ClamXAV | =0.67 | |
ClamXAV | =0.81 | |
ClamXAV | =0.54 | |
ClamXAV | =0.53 | |
ClamXAV | =0.70 | |
ClamXAV | =0.80_rc2 | |
ClamXAV | =0.60 | |
ClamXAV | =0.86 | |
ClamXAV | =0.83 | |
ClamXAV | =0.68.1 | |
ClamXAV | =0.88 | |
ClamXAV | =0.87.1 | |
ClamXAV | =0.84_rc2 | |
ClamXAV | =0.51 | |
ClamXAV | =0.52 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1614 is rated as a high severity vulnerability due to its potential to cause denial of service and allow arbitrary code execution.
To fix CVE-2006-1614, upgrade ClamAV to a version later than 0.88.1 where the vulnerability is patched.
CVE-2006-1614 affects ClamAV versions 0.80 through 0.88, including various release candidates and patches prior to 0.88.1.
Yes, CVE-2006-1614 can be exploited remotely by attackers to cause a denial of service.
The potential impacts of CVE-2006-1614 include denial of service and possibly the execution of arbitrary code on the affected systems.