10

CVE-2006-1615

Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code.  NOTE: as of 20060410, it is unclear whether this is a vulnerability, as there is some evidence that the arguments are actually being sanitized properly.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Clamav ≫ Clamav Version <= 0.88
Clamav ≫ Clamav Version 0.01
Clamav ≫ Clamav Version 0.02
Clamav ≫ Clamav Version 0.3
Clamav ≫ Clamav Version 0.03
Clamav ≫ Clamav Version 0.05
Clamav ≫ Clamav Version 0.8 Update rc3
Clamav ≫ Clamav Version 0.10
Clamav ≫ Clamav Version 0.12
Clamav ≫ Clamav Version 0.13
Clamav ≫ Clamav Version 0.14
Clamav ≫ Clamav Version 0.14 Update pre
Clamav ≫ Clamav Version 0.15
Clamav ≫ Clamav Version 0.20
Clamav ≫ Clamav Version 0.21
Clamav ≫ Clamav Version 0.22
Clamav ≫ Clamav Version 0.23
Clamav ≫ Clamav Version 0.24
Clamav ≫ Clamav Version 0.51
Clamav ≫ Clamav Version 0.52
Clamav ≫ Clamav Version 0.53
Clamav ≫ Clamav Version 0.54
Clamav ≫ Clamav Version 0.60
Clamav ≫ Clamav Version 0.60p
Clamav ≫ Clamav Version 0.65
Clamav ≫ Clamav Version 0.66
Clamav ≫ Clamav Version 0.67
Clamav ≫ Clamav Version 0.67-1
Clamav ≫ Clamav Version 0.68
Clamav ≫ Clamav Version 0.68.1
Clamav ≫ Clamav Version 0.70
Clamav ≫ Clamav Version 0.70 Update rc
Clamav ≫ Clamav Version 0.71
Clamav ≫ Clamav Version 0.72
Clamav ≫ Clamav Version 0.73
Clamav ≫ Clamav Version 0.74
Clamav ≫ Clamav Version 0.75
Clamav ≫ Clamav Version 0.75.1
Clamav ≫ Clamav Version 0.80
Clamav ≫ Clamav Version 0.80 Update rc
Clamav ≫ Clamav Version 0.80 Update rc1
Clamav ≫ Clamav Version 0.80 Update rc2
Clamav ≫ Clamav Version 0.80 Update rc3
Clamav ≫ Clamav Version 0.80 Update rc4
Clamav ≫ Clamav Version 0.81
Clamav ≫ Clamav Version 0.81 Update rc1
Clamav ≫ Clamav Version 0.82
Clamav ≫ Clamav Version 0.83
Clamav ≫ Clamav Version 0.84
Clamav ≫ Clamav Version 0.84 Update rc1
Clamav ≫ Clamav Version 0.84 Update rc2
Clamav ≫ Clamav Version 0.85
Clamav ≫ Clamav Version 0.85.1
Clamav ≫ Clamav Version 0.86
Clamav ≫ Clamav Version 0.86 Update rc1
Clamav ≫ Clamav Version 0.86.1
Clamav ≫ Clamav Version 0.86.2
Clamav ≫ Clamav Version 0.87
Clamav ≫ Clamav Version 0.87.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.35% 0.954
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

http://lists.apple.com/archives/security-announce/2006/May/msg00003.html
http://secunia.com/advisories/20077
Vendor Advisory
http://www.securityfocus.com/bid/17951
http://www.us-cert.gov/cas/techalerts/TA06-132A.html
US Government Resource
http://www.vupen.com/english/advisories/2006/1779
Vendor Advisory
http://www.trustix.org/errata/2006/0020
http://secunia.com/advisories/19570
Patch
Vendor Advisory
http://lists.suse.com/archive/suse-security-announce/2006-Apr/0002.html
Patch
Vendor Advisory
http://secunia.com/advisories/19534
Patch
Vendor Advisory
http://secunia.com/advisories/19536
Patch
Vendor Advisory
http://secunia.com/advisories/19564
Patch
Vendor Advisory
http://secunia.com/advisories/19567
Vendor Advisory
http://secunia.com/advisories/19608
Patch
Vendor Advisory
http://secunia.com/advisories/23719
Vendor Advisory
http://sourceforge.net/project/shownotes.php?release_id=407078&group_id=86638
Patch
http://up2date.astaro.com/2006/05/low_up2date_6202.html
http://www.debian.org/security/2006/dsa-1024
Patch
Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200604-06.xml
Patch
Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2006:067
http://www.securityfocus.com/bid/17388
Patch
http://www.vupen.com/english/advisories/2006/1258
Vendor Advisory
http://www.osvdb.org/24458
https://exchange.xforce.ibmcloud.com/vulnerabilities/25661