CVE-2006-1615

ClamAV < 0.88.1 - Remote Code Execution via Format String Vulnerability in Logging Code

Title source: llm
STIX 2.1

Description

Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code. NOTE: as of 20060410, it is unclear whether this is a vulnerability, as there is some evidence that the arguments are actually being sanitized properly.

References (23)

Core 23
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19567
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17951
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1258
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1779
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-132A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/24458
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19570
Various Sources x_refsource_confirm
http://up2date.astaro.com/2006/05/low_up2date_6202.html
Patch, Vendor Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200604-06.xml
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19608
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19534
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19564
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19536
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2006/May/msg00003.html
Patch, Vendor Advisory vendor-advisory x_refsource_suse
http://lists.suse.com/archive/suse-security-announce/2006-Apr/0002.html
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:067
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17388
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1024
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23719
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20077
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25661
Vendor Advisory vendor-advisory x_refsource_trustix
http://www.trustix.org/errata/2006/0020

Scores

EPSS 0.1135
EPSS Percentile 95.4%

Details

CWE
CWE-134
Status published
Products (40)
clamav/clamav 0.01
clamav/clamav 0.02
clamav/clamav 0.3
clamav/clamav 0.03
clamav/clamav 0.05
clamav/clamav 0.8 rc3
clamav/clamav 0.10
clamav/clamav 0.12
clamav/clamav 0.13
clamav/clamav 0.14 (2 CPE variants)
... and 30 more
Published Apr 06, 2006
Tracked Since Feb 18, 2026