CVE-2006-0994
Sophos Anti-Virus CAB Unpacking Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple Sophos Anti-Virus products, including Anti-Virus for Windows 5.x before 5.2.1 and 4.x before 4.05, when cabinet file inspection is enabled, allows remote attackers to execute arbitrary code via a CAB file with "invalid folder count values," which leads to heap corruption.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sophos AntiVirus. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the unpacking of Microsoft Cabinet files that contain invalid folder count values within the CAB header. Parsing of a specially crafted cabinet file can lead to an exploitable heap corruption. This vulnerability is only exposed when cabinet file inspection is explicitly enabled.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-03-03 CVE Reserved
- 2006-05-08 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/045897.html | Mailing List | |
http://secunia.com/advisories/20028 | Third Party Advisory | |
http://securityreason.com/securityalert/869 | Third Party Advisory | |
http://securitytracker.com/id?1016041 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/433272/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/17876 | Third Party Advisory | |
http://www.zerodayinitiative.com/advisories/ZDI-06-012.html | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26305 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sophos Search vendor "Sophos" | Sophos Anti-virus Search vendor "Sophos" for product "Sophos Anti-virus" | > 4.00 < 4.05 Search vendor "Sophos" for product "Sophos Anti-virus" and version " > 4.00 < 4.05" | - |
Affected
| ||||||
Sophos Search vendor "Sophos" | Sophos Anti-virus Search vendor "Sophos" for product "Sophos Anti-virus" | >= 5.0.0 < 5.2.1 Search vendor "Sophos" for product "Sophos Anti-virus" and version " >= 5.0.0 < 5.2.1" | - |
Affected
|