CVE-2006-5647: Buffer Overflow
Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name length in the CHM chunk header, aka "CHM name length memory consumption vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5647?
CVE-2006-5647 has a severity rating that indicates it can lead to potential remote code execution and denial of service.
How do I fix CVE-2006-5647?
To fix CVE-2006-5647, update Sophos Anti-Virus and Endpoint Security to versions 6.0.5 or later and Anti-Virus for Linux to 5.0.10 or later.
Which versions of Sophos Anti-Virus are affected by CVE-2006-5647?
CVE-2006-5647 affects Sophos Anti-Virus versions 4.04 through 6.0.4 and Endpoint Security versions up to 6.0.4.
Can CVE-2006-5647 lead to data breaches?
Yes, CVE-2006-5647 can potentially be exploited to execute arbitrary code, which may lead to data breaches.
What type of attack does CVE-2006-5647 facilitate?
CVE-2006-5647 facilitates denial of service attacks through memory corruption caused by malformed CHM files.