CVE-2006-5647
medium · 6.4Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name length in the CHM chunk header, aka "CHM name length memory consumption vulnerability."
6.4
CVSS
20.7%
EPSS (exploit prob.)
97th
EPSS percentile
2006-11-01
Published
AV:N/AC:L/Au:N/C:N/I:P/A:P
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sophos | anti-virus | 4.04 |
| sophos | anti-virus | 4.05 |
| sophos | anti-virus | 4.5.3 |
| sophos | anti-virus | 4.5.4 |
| sophos | anti-virus | 4.5.11 |
| sophos | anti-virus | 4.5.12 |
| sophos | anti-virus | 4.7.1 |
| sophos | anti-virus | 4.7.2 |
| sophos | anti-virus | 5.0.1 |
| sophos | anti-virus | 5.0.2 |
| sophos | anti-virus | 5.0.4 |
| sophos | anti-virus | 5.1 |
| sophos | anti-virus | 5.2 |
| sophos | anti-virus | 5.2.1 |
| sophos | anti-virus | 6.0.4 |
| sophos | endpoint_security | <= 6.04 |
Check a specific version with /api/v1/cve/match.
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=451
- http://secunia.com/advisories/22591
- http://securitytracker.com/id?1017132
- http://www.securityfocus.com/bid/20816
- http://www.sophos.com/support/knowledgebase/article/7609.html
- http://www.vupen.com/english/advisories/2006/4239
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=451
- http://secunia.com/advisories/22591
- http://securitytracker.com/id?1017132
- http://www.securityfocus.com/bid/20816
- http://www.sophos.com/support/knowledgebase/article/7609.html
- http://www.vupen.com/english/advisories/2006/4239
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-5647