CVE-2006-4626: Buffer Overflow
Published Sep 7, 2006
·Updated
Heap-based buffer overflow in alwil avast! Anti-virus Engine before 4.7.869 allows remote attackers to execute arbitrary code via a crafted LHA file that contains extended headers with file and directory names whose concatenation triggers the overflow.
Affected Software
29 affected components
ALWIL Avast Antivirus<=4.6.460
ALWIL Avast Antivirus<=4.6.763
ALWIL Avast Antivirus=4.0.168
ALWIL Avast Antivirus=4.0.172
ALWIL Avast Antivirus=4.0.183
ALWIL Avast Antivirus=4.0.202
ALWIL Avast Antivirus=4.0.211
ALWIL Avast Antivirus=4.0.229
ALWIL Avast Antivirus=4.0.235
ALWIL Avast Antivirus=4.1.260
ALWIL Avast Antivirus=4.1.268
ALWIL Avast Antivirus=4.1.278
ALWIL Avast Antivirus=4.1.287
ALWIL Avast Antivirus=4.1.289
ALWIL Avast Antivirus=4.1.304
ALWIL Avast Antivirus=4.1.319
ALWIL Avast Antivirus=4.1.335
ALWIL Avast Antivirus=4.1.342
ALWIL Avast Antivirus=4.1.357
ALWIL Avast Antivirus=4.1.389
ALWIL Avast Antivirus=4.1.396
ALWIL Avast Antivirus=4.1.412
ALWIL Avast Antivirus=4.1.418
ALWIL Avast Antivirus=4.1.501
ALWIL Avast Antivirus=4.5.518
ALWIL Avast Antivirus=4.5.549
ALWIL Avast Antivirus=4.5.561
ALWIL Avast Antivirus=4.6.603
ALWIL Avast Antivirus=4.6.623
Remediation
Patch Available
Event History
Sep 7, 2006
CVE Published
09:04 PM
Sep 8, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4626?
CVE-2006-4626 is rated as high severity due to its potential to allow remote code execution.
2
How do I fix CVE-2006-4626?
To mitigate CVE-2006-4626, users should upgrade to Avast Antivirus version 4.7.869 or later.
3
What software is affected by CVE-2006-4626?
CVE-2006-4626 affects several versions of Avast Antivirus prior to version 4.7.869.
4
What kind of attack does CVE-2006-4626 facilitate?
CVE-2006-4626 allows remote attackers to execute arbitrary code through a specially crafted LHA file.
5
Is there a workaround for CVE-2006-4626?
The best workaround for CVE-2006-4626 is to avoid opening LHA files from untrusted sources until the software has been updated.