CVE-2006-6627: Buffer Overflow
Integer overflow in the packed PE file parsing implementation in BitDefender products before 20060829, including Antivirus, Antivirus Plus, Internet Security, Mail Protection for Enterprises, and Online Scanner; and BitDefender products for Microsoft ISA Server and Exchange 5.5 through 2003; allows remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow, aka the "cevakrnl.xmd vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6627?
CVE-2006-6627 is classified as a high severity vulnerability due to the potential for integer overflow exploitation.
How do I fix CVE-2006-6627?
To fix CVE-2006-6627, update your BitDefender products to the version released on or after August 29, 2006.
Which BitDefender products are affected by CVE-2006-6627?
CVE-2006-6627 affects several BitDefender products including Antivirus, Internet Security, and Mail Protection for Enterprises.
What type of vulnerability is CVE-2006-6627?
CVE-2006-6627 is an integer overflow vulnerability present in the PE file parsing implementation.
Can CVE-2006-6627 be exploited remotely?
Yes, CVE-2006-6627 can potentially be exploited remotely through crafted PE files.