First published: Thu Apr 06 2006(Updated: )
The cli_bitset_set function in libclamav/others.c in Clam AntiVirus (ClamAV) before 0.88.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger an "invalid memory access."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamXAV | =0.51 | |
ClamXAV | =0.52 | |
ClamXAV | =0.53 | |
ClamXAV | =0.54 | |
ClamXAV | =0.60 | |
ClamXAV | =0.65 | |
ClamXAV | =0.67 | |
ClamXAV | =0.68 | |
ClamXAV | =0.68.1 | |
ClamXAV | =0.70 | |
ClamXAV | =0.75.1 | |
ClamXAV | =0.80 | |
ClamXAV | =0.80_rc1 | |
ClamXAV | =0.80_rc2 | |
ClamXAV | =0.80_rc3 | |
ClamXAV | =0.80_rc4 | |
ClamXAV | =0.81 | |
ClamXAV | =0.82 | |
ClamXAV | =0.83 | |
ClamXAV | =0.84 | |
ClamXAV | =0.84_rc1 | |
ClamXAV | =0.84_rc2 | |
ClamXAV | =0.85 | |
ClamXAV | =0.85.1 | |
ClamXAV | =0.86 | |
ClamXAV | =0.86.1 | |
ClamXAV | =0.86.2 | |
ClamXAV | =0.87 | |
ClamXAV | =0.87.1 | |
ClamXAV | =0.88 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1630 is classified as a denial of service vulnerability that can be exploited by remote attackers.
To fix CVE-2006-1630, upgrade Clam AntiVirus to version 0.88.1 or later.
CVE-2006-1630 affects multiple versions of ClamAV, including 0.84, 0.80, and various release candidates leading up to 0.88.
If exploited, CVE-2006-1630 can lead to an invalid memory access, causing the ClamAV service to crash.
There are no known workarounds for CVE-2006-1630; the best practice is to upgrade the software.