CVE-2006-4018
Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to execute arbitrary code via a crafted UPX packed file containing sections with large rsize values.
- Affected products
- Clamav
- Clamav
- = 0.81, 0.82, 0.83, 0.84, 0.85, 0.85.1, 0.86, 0.86.1, 0.86.2, 0.87, 0.87.1, 0.88, 0.88.1, 0.88.2, 0.88.3
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 19.1% (97th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2006-08-08
CVE-2006-4018 at NVD
1 known exploit for CVE-2006-4018
Proof-of-concept code and exploit modules indexed by Sploitus