CVE-2007-6596: Input Validation
Published Dec 31, 2007
·Updated
ClamAV 0.92 does not recognize Base64 UUEncoded archives, which allows remote attackers to bypass the scanner via a Base64-UUEncoded file.
Affected Software
1 affected component
Clam Anti-Virus clamav=0.92
Event History
Dec 31, 2007
CVE Published
07:46 PM
Jan 1, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6596?
CVE-2007-6596 is considered a high-severity vulnerability as it allows remote attackers to bypass ClamAV's scanning capabilities.
2
How do I fix CVE-2007-6596?
To fix CVE-2007-6596, upgrade ClamAV to a version later than 0.92 that properly handles Base64 UUEncoded archives.
3
What software does CVE-2007-6596 affect?
CVE-2007-6596 specifically affects ClamAV version 0.92.
4
Can CVE-2007-6596 lead to malware infection?
Yes, CVE-2007-6596 can potentially lead to malware infection as it allows malicious files to evade scanning.
5
Is CVE-2007-6596 limited to specific file types?
CVE-2007-6596 is related to the way ClamAV handles Base64 UUEncoded archives, which may impact various file types that are encoded in this format.