CVE-2006-6676: Buffer Overflow
Published Dec 21, 2006
·Updated
Integer overflow in the (a) OLE2 and (b) CHM parsers for ESET NOD32 Antivirus before 1.1743 allows remote attackers to execute arbitrary code via a crafted (1) .DOC or (2) .CAB file that triggers a heap-based buffer overflow.
Affected Software
4 affected components
Eset Software Nod32 Antivirus=1.0.11
Eset Software Nod32 Antivirus=1.0.12
Eset Software Nod32 Antivirus<=1.1742
Eset Software Nod32 Antivirus=1.0.13
Remediation
Patch Available
Patch Available
Event History
Dec 21, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:28 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-6676?
CVE-2006-6676 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2006-6676?
To fix CVE-2006-6676, upgrade to ESET NOD32 Antivirus version 1.1743 or later.
3
What types of files can exploit CVE-2006-6676?
CVE-2006-6676 can be exploited through crafted .DOC and .CAB files.
4
Which versions of ESET NOD32 Antivirus are affected by CVE-2006-6676?
CVE-2006-6676 affects ESET NOD32 Antivirus versions up to 1.1742.
5
Who can be targeted by CVE-2006-6676?
CVE-2006-6676 can potentially target users of ESET NOD32 Antivirus, making them vulnerable to attacks via crafted files.