First published: Wed Nov 01 2006(Updated: )
Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name length in the CHM chunk header, aka "CHM name length memory consumption vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Anti-Virus for Sophos Central macOS | =4.04 | |
Sophos Anti-Virus for Sophos Central macOS | =5.2 | |
Sophos Anti-Virus for Sophos Central macOS | =5.0.2 | |
Sophos Anti-Virus for Sophos Central macOS | =4.5.12 | |
Sophos Endpoint Security And Control | <=6.04 | |
Sophos Anti-Virus for Sophos Central macOS | =4.5.11 | |
Sophos Anti-Virus for Sophos Central macOS | =4.7.1 | |
Sophos Anti-Virus for Sophos Central macOS | =4.7.2 | |
Sophos Anti-Virus for Sophos Central macOS | =5.0.4 | |
Sophos Anti-Virus for Sophos Central macOS | =5.2.1 | |
Sophos Anti-Virus for Sophos Central macOS | =4.05 | |
Sophos Anti-Virus for Sophos Central macOS | =4.5.3 | |
Sophos Anti-Virus for Sophos Central macOS | =4.5.4 | |
Sophos Anti-Virus for Sophos Central macOS | =6.0.4 | |
Sophos Anti-Virus for Sophos Central macOS | =5.1 | |
Sophos Anti-Virus for Sophos Central macOS | =5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5647 has a severity rating that indicates it can lead to potential remote code execution and denial of service.
To fix CVE-2006-5647, update Sophos Anti-Virus and Endpoint Security to versions 6.0.5 or later and Anti-Virus for Linux to 5.0.10 or later.
CVE-2006-5647 affects Sophos Anti-Virus versions 4.04 through 6.0.4 and Endpoint Security versions up to 6.0.4.
Yes, CVE-2006-5647 can potentially be exploited to execute arbitrary code, which may lead to data breaches.
CVE-2006-5647 facilitates denial of service attacks through memory corruption caused by malformed CHM files.