First published: Wed Dec 13 2006(Updated: )
The (1) VetMONNT.sys and (2) VetFDDNT.sys drivers in CA Anti-Virus 2007 8.1, Anti-Virus for Vista Beta 8.2, and CA Internet Security Suite 2007 v3.0 do not properly handle NULL buffers, which allows local users with administrative access to cause a denial of service (system crash) via certain IOCTLs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom eTrust Antivirus | =8.1 | |
Broadcom eTrust Antivirus | =8.2-beta | |
Broadcom Internet Security Suite | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6496 has a high severity due to its potential to cause a system crash when exploited.
To fix CVE-2006-6496, update your CA Anti-Virus or Internet Security Suite to the latest version that addresses this vulnerability.
CVE-2006-6496 affects CA Anti-Virus 2007 8.1, Anti-Virus for Vista Beta 8.2, and CA Internet Security Suite 2007 v3.0.
The vulnerability in CVE-2006-6496 is triggered by improper handling of NULL buffers within the affected drivers.
Yes, local user privileges with administrative access are required to exploit CVE-2006-6496.