CVE-2006-4438
Summary
| CVE | CVE-2006-4438 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-20 23:07:00 UTC |
| Updated | 2011-03-08 02:40:00 UTC |
| Description | Heap-based buffer overflow in SpIDer for Dr.Web Scanner for Linux 4.33, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LHA archive with an extended header that contains a long directory name. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Doctor Web Ltd | Dr.web | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Dr.Web LHA Directory Name Buffer Overflow - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| [Full-disclosure] Dr.Web 4.33 antivirus LHA long directory name heap overflow | FULLDISC | lists.grok.org.uk | |
| Dr. Web Anti-Virus LHA Archive Heap Buffer-Overflow Vulnerability | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.