← All CVEs

CVE-2006-5645

medium · 5

Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of archives" is set, allows remote attackers to cause a denial of service (infinite loop) via a malformed RAR archive with an Archive Header section with the head_size and pack_size fields set to zero.

5
CVSS
17.5%
EPSS (exploit prob.)
97th
EPSS percentile
2006-11-01
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-399

Affected products

VendorProductAffected versions
sophosanti-virus4.04
sophosanti-virus4.05
sophosanti-virus4.5.3
sophosanti-virus4.5.4
sophosanti-virus4.5.11
sophosanti-virus4.5.12
sophosanti-virus4.7.1
sophosanti-virus4.7.2
sophosanti-virus5.0.1
sophosanti-virus5.0.2
sophosanti-virus5.0.4
sophosanti-virus5.1
sophosanti-virus5.2
sophosanti-virus5.2.1
sophosanti-virus6.0.4
sophosendpoint_security<= 6.04

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-5645