CVE-2006-6406Anti-virus Clamav vulnerability

6 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
2.4%
top 15.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10
Latest updateMay 1

Description

Clam AntiVirus (ClamAV) 0.88.6 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianclamav/clamav< 0.88.7-1+3

🔴Vulnerability Details

3
GHSA
GHSA-xqx5-63qm-w35c: Clam AntiVirus (ClamAV) 02022-05-01
CVEList
CVE-2006-6406: Clam AntiVirus (ClamAV) 02006-12-10
OSV
CVE-2006-6406: Clam AntiVirus (ClamAV) 02006-12-10

📋Vendor Advisories

1
Debian
CVE-2006-6406: clamav - Clam AntiVirus (ClamAV) 0.88.6 allows remote attackers to bypass virus detection...2006

💬Community

1
Bugzilla
CVE-2006-6406: clamav <= 0.88.6 virus detection bypass2006-12-10
CVE-2006-6406 — Clam Anti-virus Clamav vulnerability | cvebase