First published: Sun Dec 10 2006(Updated: )
Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a denial of service (crash) via a malformed base64-encoded MIME attachment that triggers a null pointer dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamXAV | =0.84 | |
ClamXAV | =0.80 | |
ClamXAV | =0.84_rc1 | |
ClamXAV | =0.80_rc3 | |
ClamXAV | =0.80_rc4 | |
ClamXAV | <=0.88 | |
ClamXAV | =0.86.1 | |
ClamXAV | =0.82 | |
ClamXAV | =0.85.1 | |
ClamXAV | =. | |
ClamXAV | =0.87 | |
ClamXAV | =0.86_rc1 | |
ClamXAV | =0.85 | |
ClamXAV | =0.80_rc1 | |
ClamXAV | =0.86.2 | |
ClamXAV | =0.81 | |
ClamXAV | =0.81_rc1 | |
ClamXAV | =0.80_rc2 | |
ClamXAV | =0.86 | |
ClamXAV | =0.83 | |
ClamXAV | =0.87.1 | |
ClamXAV | =0.84_rc2 | |
ClamAV | <=0.88 | |
ClamAV | =. | |
ClamAV | =0.80 | |
ClamAV | =0.80_rc1 | |
ClamAV | =0.80_rc2 | |
ClamAV | =0.80_rc3 | |
ClamAV | =0.80_rc4 | |
ClamAV | =0.81 | |
ClamAV | =0.81_rc1 | |
ClamAV | =0.82 | |
ClamAV | =0.83 | |
ClamAV | =0.84 | |
ClamAV | =0.84_rc1 | |
ClamAV | =0.84_rc2 | |
ClamAV | =0.85 | |
ClamAV | =0.85.1 | |
ClamAV | =0.86 | |
ClamAV | =0.86.1 | |
ClamAV | =0.86.2 | |
ClamAV | =0.86_rc1 | |
ClamAV | =0.87 | |
ClamAV | =0.87.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5874 is classified as a vulnerability that can lead to a denial of service due to a null pointer dereference.
To fix CVE-2006-5874, you should upgrade to ClamAV version 0.88 or later.
CVE-2006-5874 affects ClamAV versions 0.88 and earlier.
CVE-2006-5874 enables remote attackers to cause a denial of service by sending a malformed base64-encoded MIME attachment.
There are no specific workarounds for CVE-2006-5874 other than upgrading to a safe version of ClamAV.