VDB
CVE-2006-1615
CVE-2006-1615
PUBLISHED
CVSS 10 CRITICAL
Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code. NOTE: as of 20060410, it is unclear whether this is a vulnerability, as there is some evidence that the arguments are actually being sanitized properly.
EPSS 11.35% · 95.7th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
11.35%
95.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| clamav | clamav | 0.86, 0, 0.01 |
| n/a | n/a | n/a |
Timeline
- Apr 6, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 18, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- ADV-2006-1779 vdb
- 24458 vdb
- 2006-0020 vendor-advisory
- 19608 third-party-advisory
- 19564 third-party-advisory
- 19536 third-party-advisory
- APPLE-SA-2006-05-11 vendor-advisory
- clamav-output-format-string(25661) vdb
- http://secunia.com/advisories/19534 patch
- http://secunia.com/advisories/19570 patch
- http://secunia.com/advisories/20077 advisory
- http://secunia.com/advisories/23719 advisory
- http://sourceforge.net/project/shownotes.php?release_id=407078&group_id=86638 patch
- http://up2date.astaro.com/2006/05/low_up2date_6202.html technical
- http://www.securityfocus.com/bid/17951 technical
- http://lists.suse.com/archive/suse-security-announce/2006-Apr/0002.html patch
- http://secunia.com/advisories/19567 advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:067 technical
- http://www.us-cert.gov/cas/techalerts/TA06-132A.html advisory
- http://www.vupen.com/english/advisories/2006/1258 advisory
…and 4 more