CVE-2006-5874: Null Pointer Dereference
Published Dec 10, 2006
·Updated
Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a denial of service (crash) via a malformed base64-encoded MIME attachment that triggers a null pointer dereference.
Affected Software
22 affected components
Clam Anti-Virus clamav<=0.88
Clam Anti-Virus clamav=.
Clam Anti-Virus clamav=0.80
Clam Anti-Virus clamav=0.80_rc1
Clam Anti-Virus clamav=0.80_rc2
Clam Anti-Virus clamav=0.80_rc3
Clam Anti-Virus clamav=0.80_rc4
Clam Anti-Virus clamav=0.81
Clam Anti-Virus clamav=0.81_rc1
Clam Anti-Virus clamav=0.82
Clam Anti-Virus clamav=0.83
Clam Anti-Virus clamav=0.84
Clam Anti-Virus clamav=0.84_rc1
Clam Anti-Virus clamav=0.84_rc2
Clam Anti-Virus clamav=0.85
Clam Anti-Virus clamav=0.85.1
Clam Anti-Virus clamav=0.86
Clam Anti-Virus clamav=0.86.1
Clam Anti-Virus clamav=0.86.2
Clam Anti-Virus clamav=0.86_rc1
Clam Anti-Virus clamav=0.87
Clam Anti-Virus clamav=0.87.1
Remediation
Patch Available
Event History
Dec 10, 2006
CVE Published
02:28 AM
Data Sourced
via NVD·02:28 AM
RemedyDescriptionSeverityAffected Software
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-5874?
CVE-2006-5874 is classified as a vulnerability that can lead to a denial of service due to a null pointer dereference.
2
How do I fix CVE-2006-5874?
To fix CVE-2006-5874, you should upgrade to ClamAV version 0.88 or later.
3
What versions of ClamAV are affected by CVE-2006-5874?
CVE-2006-5874 affects ClamAV versions 0.88 and earlier.
4
What type of attack does CVE-2006-5874 enable?
CVE-2006-5874 enables remote attackers to cause a denial of service by sending a malformed base64-encoded MIME attachment.
5
Is there a workaround for CVE-2006-5874?
There are no specific workarounds for CVE-2006-5874 other than upgrading to a safe version of ClamAV.