CVE-2006-1615
ClamAV < 0.88.1 - Remote Code Execution via Format String Vulnerability in Logging Code
Title source: llmDescription
Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code. NOTE: as of 20060410, it is unclear whether this is a vulnerability, as there is some evidence that the arguments are actually being sanitized properly.
References (23)
Core 23
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/19567
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/17951
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1258
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1779
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-132A.html
Patch x_refsource_confirm
http://sourceforge.net/project/shownotes.php?release_id=407078&group_id=86638
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/24458
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/19570
Various Sources x_refsource_confirm
http://up2date.astaro.com/2006/05/low_up2date_6202.html
Patch, Vendor Advisory vendor-advisory
x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200604-06.xml
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/19608
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/19534
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/19564
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/19536
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2006/May/msg00003.html
Patch, Vendor Advisory vendor-advisory
x_refsource_suse
http://lists.suse.com/archive/suse-security-announce/2006-Apr/0002.html
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:067
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/17388
Patch, Vendor Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2006/dsa-1024
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23719
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/20077
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25661
Vendor Advisory vendor-advisory
x_refsource_trustix
http://www.trustix.org/errata/2006/0020
Scores
EPSS
0.1135
EPSS Percentile
95.4%
Details
CWE
CWE-134
Status
published
Products (40)
clamav/clamav
0.01
clamav/clamav
0.02
clamav/clamav
0.3
clamav/clamav
0.03
clamav/clamav
0.05
clamav/clamav
0.8 rc3
clamav/clamav
0.10
clamav/clamav
0.12
clamav/clamav
0.13
clamav/clamav
0.14 (2 CPE variants)
... and 30 more
Published
Apr 06, 2006
Tracked Since
Feb 18, 2026