CVE Vulnerabilities

CVE-2006-1989

Published: May 01, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Buffer overflow in the get_database function in the HTTP client in Freshclam in ClamAV 0.80 to 0.88.1 might allow remote web servers to execute arbitrary code via long HTTP headers.

Affected Software

NameVendorStart VersionEnd Version
ClamavClam_anti-virus0.88 (including)0.88 (including)
ClamavClam_anti-virus0.88.1 (including)0.88.1 (including)
ClamavUbuntudapper*
ClamavUbuntudevel*
ClamavUbuntuedgy*
ClamavUbuntufeisty*

References