CVE-2006-4182: Buffer Overflow
Integer overflow in ClamAV 0.88.1 and 0.88.4, and other versions before 0.88.5, allows remote attackers to cause a denial of service (scanning service crash) and execute arbitrary code via a crafted Portable Executable (PE) file that leads to a heap-based buffer overflow when less memory is allocated than expected.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4182?
The severity of CVE-2006-4182 is high due to its potential for causing denial of service and remote code execution.
How do I fix CVE-2006-4182?
To fix CVE-2006-4182, update ClamAV to version 0.88.5 or later.
Who is affected by CVE-2006-4182?
CVE-2006-4182 affects multiple versions of ClamAV prior to 0.88.5, including versions as low as 0.15.
What is the impact of CVE-2006-4182?
The impact of CVE-2006-4182 includes crashes of the scanning service and the possibility of remote code execution.
How does CVE-2006-4182 work?
CVE-2006-4182 exploits an integer overflow leading to a heap-based buffer overflow when parsing crafted PE files.