{"api_version":"1","generated_at":"2026-07-24T21:02:41+00:00","cve":"CVE-2006-4438","urls":{"html":"https://cve.report/CVE-2006-4438","api":"https://cve.report/api/cve/CVE-2006-4438.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-4438","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-4438"},"summary":{"title":"CVE-2006-4438","description":"Heap-based buffer overflow in SpIDer for Dr.Web Scanner for Linux 4.33, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LHA archive with an extended header that contains a long directory name.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-09-20 23:07:00","updated_at":"2011-03-08 02:40:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://www.vupen.com/english/advisories/2006/3719","name":"ADV-2006-3719","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22019","name":"22019","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Dr.Web LHA Directory Name Buffer Overflow - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/049552.html","name":"20060420 Dr.Web 4.33 antivirus LHA long directory name heap overflow","refsource":"FULLDISC","tags":[],"title":"[Full-disclosure] Dr.Web 4.33 antivirus LHA long directory name\theap overflow","mime":"text/x-c","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/20119","name":"20119","refsource":"BID","tags":[],"title":"Dr. Web Anti-Virus LHA Archive Heap Buffer-Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-4438","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-4438","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"4438","vulnerable":"1","versionEndIncluding":"4.33_for_linux","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"doctor_web_ltd","cpe5":"dr.web","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-4438","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Heap-based buffer overflow in SpIDer for Dr.Web Scanner for Linux 4.33, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LHA archive with an extended header that contains a long directory name."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20119","refsource":"BID","url":"http://www.securityfocus.com/bid/20119"},{"name":"22019","refsource":"SECUNIA","url":"http://secunia.com/advisories/22019"},{"name":"ADV-2006-3719","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/3719"},{"name":"20060420 Dr.Web 4.33 antivirus LHA long directory name heap overflow","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/049552.html"}]}},"nvd":{"publishedDate":"2006-09-20 23:07:00","lastModifiedDate":"2011-03-08 02:40:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:doctor_web_ltd:dr.web:*:*:*:*:*:*:*:*","versionEndIncluding":"4.33_for_linux","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"4438","Ordinal":"19770","Title":"CVE-2006-4438","CVE":"CVE-2006-4438","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"4438","Ordinal":"1","NoteData":"Heap-based buffer overflow in SpIDer for Dr.Web Scanner for Linux 4.33, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LHA archive with an extended header that contains a long directory name.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"4438","Ordinal":"2","NoteData":"2006-09-20","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"4438","Ordinal":"3","NoteData":"2006-09-25","Type":"Other","Title":"Modified"}]}}}