VulnerabilityModified
CVE-2006-4438
Heap-based buffer overflow in SpIDer for Dr.Web Scanner for Linux 4.33, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LHA archive with an extended header that contains a long directory name.
MEDIUM 6.4EPSS 10.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.5%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Heap-based buffer overflow in SpIDer for Dr.Web Scanner for Linux 4.33, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LHA archive with an extended header that contains a long directory name.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 10.50% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- doctor web ltd/dr.web
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/049552.html
- http://secunia.com/advisories/22019Vendor Advisory
- http://www.securityfocus.com/bid/20119
- http://www.vupen.com/english/advisories/2006/3719
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/049552.html
- http://secunia.com/advisories/22019Vendor Advisory
- http://www.securityfocus.com/bid/20119
- http://www.vupen.com/english/advisories/2006/3719
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.