CVE-2006-4018: Buffer Overflow
Published Aug 8, 2006
·Updated
Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to execute arbitrary code via a crafted UPX packed file containing sections with large rsize values.
Affected Software
19 affected components
clamav clamav=0.86.2
clamav clamav=0.81
clamav clamav=0.86
clamav clamav=0.85
clamav clamav=0.84
clamav clamav=0.86-rc1
clamav clamav=0.87.1
clamav clamav=0.88
clamav clamav=0.86.1
clamav clamav=0.88.1
clamav clamav=0.85.1
clamav clamav=0.81-rc1
clamav clamav=0.84-rc1
clamav clamav=0.88.2
clamav clamav=0.83
clamav clamav=0.87
clamav clamav=0.84-rc2
clamav clamav=0.88.3
clamav clamav=0.82
Remediation
Patch Available
Patch Available
Event History
Aug 8, 2006
CVE Published
08:04 PM
Aug 9, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4018?
CVE-2006-4018 is considered a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2006-4018?
To mitigate CVE-2006-4018, upgrade ClamAV to version 0.88.4 or later.
3
Who is affected by CVE-2006-4018?
CVE-2006-4018 affects Clam AntiVirus versions from 0.81 through 0.88.3.
4
What type of vulnerability is CVE-2006-4018?
CVE-2006-4018 is a heap-based buffer overflow vulnerability.
5
What can attackers achieve through CVE-2006-4018?
Attackers can execute arbitrary code on the affected system by exploiting CVE-2006-4018.