First published: Mon May 01 2006(Updated: )
Buffer overflow in the get_database function in the HTTP client in Freshclam in ClamAV 0.80 to 0.88.1 might allow remote web servers to execute arbitrary code via long HTTP headers.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamXAV | =0.88 | |
ClamXAV | =0.88.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1989 has a high severity rating due to the potential for remote code execution.
To fix CVE-2006-1989, upgrade ClamAV to version 0.88.2 or later.
CVE-2006-1989 affects ClamAV versions 0.80 to 0.88.1.
CVE-2006-1989 is caused by a buffer overflow in the get_database function of the Freshclam HTTP client.
There are no known workarounds for CVE-2006-1989; upgrading is the recommended action.