First published: Wed Sep 20 2006(Updated: )
Heap-based buffer overflow in SpIDer for Dr.Web Scanner for Linux 4.33, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LHA archive with an extended header that contains a long directory name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dr.Web Antivirus | <=4.33_for_linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4438 is classified as critical due to its potential for remote code execution.
To mitigate CVE-2006-4438, update Dr.Web Scanner to the latest version beyond 4.33.
CVE-2006-4438 affects Dr.Web Scanner for Linux version 4.33 and possibly earlier versions.
Yes, CVE-2006-4438 can be exploited remotely through a malicious LHA archive.
The attack vector for CVE-2006-4438 involves using a specially crafted LHA archive with a long directory name.