First published: Sun Dec 10 2006(Updated: )
Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a denial of service (crash) via a malformed base64-encoded MIME attachment that triggers a null pointer dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco ClamAV | <=0.88 | |
Cisco ClamAV | =. | |
Cisco ClamAV | =0.80 | |
Cisco ClamAV | =0.80_rc1 | |
Cisco ClamAV | =0.80_rc2 | |
Cisco ClamAV | =0.80_rc3 | |
Cisco ClamAV | =0.80_rc4 | |
Cisco ClamAV | =0.81 | |
Cisco ClamAV | =0.81_rc1 | |
Cisco ClamAV | =0.82 | |
Cisco ClamAV | =0.83 | |
Cisco ClamAV | =0.84 | |
Cisco ClamAV | =0.84_rc1 | |
Cisco ClamAV | =0.84_rc2 | |
Cisco ClamAV | =0.85 | |
Cisco ClamAV | =0.85.1 | |
Cisco ClamAV | =0.86 | |
Cisco ClamAV | =0.86.1 | |
Cisco ClamAV | =0.86.2 | |
Cisco ClamAV | =0.86_rc1 | |
Cisco ClamAV | =0.87 | |
Cisco ClamAV | =0.87.1 | |
<=0.88 | ||
=. | ||
=0.80 | ||
=0.80_rc1 | ||
=0.80_rc2 | ||
=0.80_rc3 | ||
=0.80_rc4 | ||
=0.81 | ||
=0.81_rc1 | ||
=0.82 | ||
=0.83 | ||
=0.84 | ||
=0.84_rc1 | ||
=0.84_rc2 | ||
=0.85 | ||
=0.85.1 | ||
=0.86 | ||
=0.86.1 | ||
=0.86.2 | ||
=0.86_rc1 | ||
=0.87 | ||
=0.87.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5874 is classified as a vulnerability that can lead to a denial of service due to a null pointer dereference.
To fix CVE-2006-5874, you should upgrade to ClamAV version 0.88 or later.
CVE-2006-5874 affects ClamAV versions 0.88 and earlier.
CVE-2006-5874 enables remote attackers to cause a denial of service by sending a malformed base64-encoded MIME attachment.
There are no specific workarounds for CVE-2006-5874 other than upgrading to a safe version of ClamAV.