CVE-2007-6336: Buffer Overflow
Published Dec 20, 2007
·Updated
Off-by-one error in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MS-ZIP compressed CAB file.
Affected Software
1 affected component
Clam Anti-Virus clamav<=0.91
Remediation
Patch Available
Event History
Dec 20, 2007
CVE Published
01:46 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6336?
CVE-2007-6336 is considered a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2007-6336?
To fix CVE-2007-6336, upgrade ClamAV to version 0.92 or later.
3
What versions of ClamAV are affected by CVE-2007-6336?
ClamAV versions prior to 0.92 are affected by CVE-2007-6336.
4
What type of attack does CVE-2007-6336 involve?
CVE-2007-6336 involves remote code execution through a crafted MS-ZIP compressed CAB file.
5
Who can exploit CVE-2007-6336?
Remote attackers can exploit CVE-2007-6336 to execute arbitrary code.