First published: Thu Dec 20 2007(Updated: )
Off-by-one error in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MS-ZIP compressed CAB file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamXAV | <=0.91 | |
ClamAV | <=0.91 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6336 is considered a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2007-6336, upgrade ClamAV to version 0.92 or later.
ClamAV versions prior to 0.92 are affected by CVE-2007-6336.
CVE-2007-6336 involves remote code execution through a crafted MS-ZIP compressed CAB file.
Remote attackers can exploit CVE-2007-6336 to execute arbitrary code.