CVE-2006-6293: Buffer Overflow
Published Dec 5, 2006
·Updated
Heap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to execute arbitrary code via a crafted CHM file. NOTE: this issue has at least a partial overlap with CVE-2006-6294.
Affected Software
25 affected components
F-Prot F-Prot Antivirus=3.11b
F-Prot F-Prot Antivirus=3.16b
F-Prot F-Prot Antivirus=3.14
F-Prot F-Prot Antivirus=3.13a
F-Prot F-Prot Antivirus=3.16c
F-Prot F-Prot Antivirus=3.13
F-Prot F-Prot Antivirus=3.15
F-Prot F-Prot Antivirus=3.16e
F-Prot F-Prot Antivirus=3.12c
F-Prot F-Prot Antivirus=3.15a
F-Prot F-Prot Antivirus=3.12a
F-Prot F-Prot Antivirus=3.12b
F-Prot F-Prot Antivirus<=4.6.6
F-Prot F-Prot Antivirus=3.16
F-Prot F-Prot Antivirus=3.14a
F-Prot F-Prot Antivirus=3.14c
F-Prot F-Prot Antivirus=3.16d
F-Prot F-Prot Antivirus=3.14d
F-Prot F-Prot Antivirus=3.16f
F-Prot F-Prot Antivirus=3.12
F-Prot F-Prot Antivirus=3.15b
F-Prot F-Prot Antivirus=3.14e
F-Prot F-Prot Antivirus=3.14b
F-Prot F-Prot Antivirus=3.12d
F-Prot F-Prot Antivirus=3.16a
Remediation
Patch Available
Event History
Dec 5, 2006
CVE Published
11:28 AM
Data Sourced
via NVD·11:28 AM
RemedyDescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6293?
CVE-2006-6293 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2006-6293?
To fix CVE-2006-6293, update F-Prot Antivirus to version 4.6.7 or later.
3
What causes the CVE-2006-6293 vulnerability?
CVE-2006-6293 is caused by a heap-based buffer overflow when processing crafted CHM files.
4
Which versions of F-Prot Antivirus are affected by CVE-2006-6293?
CVE-2006-6293 affects F-Prot Antivirus versions prior to 4.6.7, including multiple earlier versions such as 3.11b and 3.16.
5
Is CVE-2006-6293 exploitable without user intervention?
No, CVE-2006-6293 requires user-assisted actions, such as opening a crafted CHM file, for exploitation.