// For flags

CVE-2006-5646

Sophos AntiVirus - '.CHM' File Heap Overflow (PoC)

Severity Score

9.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when archive scanning is enabled, allows remote attackers to trigger a denial of service (memory corruption) via a CHM file with an LZX decompression header that specifies a Window_size of 0.

Desbordamiento de búfer basado en montón en Sophos Anti-Virus y Endpoint Security versiones anteriores a 6.0.5, Anti-Virus para Linux anteriores a 5.0.10, y otras plataformas anteriores a 4.11, cuando el escaneo de archivos está habilitado, permite a atacantes remotos disparar una denegación de servicio (corrupción de memoria) a través de un archivo CHM con una cabecera de descompresión LZX que especifica un tamaño de ventana 0.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-11-01 CVE Reserved
  • 2006-11-01 CVE Published
  • 2006-12-10 First Exploit
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.04
Search vendor "Sophos" for product "Anti-virus" and version "4.04"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.05
Search vendor "Sophos" for product "Anti-virus" and version "4.05"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.5.3
Search vendor "Sophos" for product "Anti-virus" and version "4.5.3"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.5.4
Search vendor "Sophos" for product "Anti-virus" and version "4.5.4"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.5.11
Search vendor "Sophos" for product "Anti-virus" and version "4.5.11"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.5.12
Search vendor "Sophos" for product "Anti-virus" and version "4.5.12"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.7.1
Search vendor "Sophos" for product "Anti-virus" and version "4.7.1"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.7.2
Search vendor "Sophos" for product "Anti-virus" and version "4.7.2"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
5.0.1
Search vendor "Sophos" for product "Anti-virus" and version "5.0.1"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
5.0.2
Search vendor "Sophos" for product "Anti-virus" and version "5.0.2"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
5.0.4
Search vendor "Sophos" for product "Anti-virus" and version "5.0.4"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
5.1
Search vendor "Sophos" for product "Anti-virus" and version "5.1"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
5.2
Search vendor "Sophos" for product "Anti-virus" and version "5.2"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
5.2.1
Search vendor "Sophos" for product "Anti-virus" and version "5.2.1"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
6.0.4
Search vendor "Sophos" for product "Anti-virus" and version "6.0.4"
-
Affected
Sophos
Search vendor "Sophos"
Endpoint Security
Search vendor "Sophos" for product "Endpoint Security"
<= 6.04
Search vendor "Sophos" for product "Endpoint Security" and version " <= 6.04"
-
Affected