Vulnerability Name:

CVE-2006-5647 (CCN-29924)

Assigned:2006-10-27
Published:2006-10-27
Updated:2011-03-07
Summary:Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name length in the CHM chunk header, aka "CHM name length memory consumption vulnerability."
CVSS v3 Severity:8.2 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): High
CVSS v2 Severity:6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P)
5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
8.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:C)
6.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:C/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Complete
Vulnerability Type:CWE-119
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2006-5647

Source: IDEFENSE
Type: UNKNOWN
20061208 Sophos Antivirus CHM Chunk Name Length Memory Corruption Vulnerability

Source: CCN
Type: SA22591
Sophos Anti-Virus RAR and CHM Denial of Service Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
22591

Source: CCN
Type: SECTRACK ID: 1017132
Sophos Anti-Virus Bugs in Processing Petite Archives, RAR Archives, and CHM Files Let Remote Users Deny Service

Source: SECTRACK
Type: UNKNOWN
1017132

Source: CCN
Type: OSVDB ID: 30114
Sophos Anti-Virus Crafted CHM Chunk Header Handling DoS

Source: BID
Type: UNKNOWN
20816

Source: CCN
Type: BID-20816
Sophos Antivirus Multiple Denial of Service and Memory Corruption Vulnerabilities

Source: CCN
Type: Sophos Support Knowledgebase Article 17609
Advisory: Vulnerabilities reported by iDefense

Source: CONFIRM
Type: UNKNOWN
http://www.sophos.com/support/knowledgebase/article/7609.html

Source: VUPEN
Type: Vendor Advisory
ADV-2006-4239

Source: XF
Type: UNKNOWN
sophos-chm-header-dos(29924)

Source: CCN
Type: iDefense Labs PUBLIC ADVISORY: 12.08.06
Sophos Antivirus CHM Chunk Name Length Memory Corruption Vulnerability

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sophos:anti-virus:4.04:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:anti-virus:4.05:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:anti-virus:4.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:anti-virus:4.5.4:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:anti-virus:4.5.11:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:anti-virus:4.5.12:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:anti-virus:4.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:anti-virus:4.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:anti-virus:5.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:anti-virus:5.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:anti-virus:5.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:anti-virus:5.1:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:anti-virus:5.2:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:anti-virus:5.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:anti-virus:6.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:endpoint_security:*:*:*:*:*:*:*:* (Version <= 6.04)

  • * Denotes that component is vulnerable
    BACK
    sophos anti-virus 4.04
    sophos anti-virus 4.05
    sophos anti-virus 4.5.3
    sophos anti-virus 4.5.4
    sophos anti-virus 4.5.11
    sophos anti-virus 4.5.12
    sophos anti-virus 4.7.1
    sophos anti-virus 4.7.2
    sophos anti-virus 5.0.1
    sophos anti-virus 5.0.2
    sophos anti-virus 5.0.4
    sophos anti-virus 5.1
    sophos anti-virus 5.2
    sophos anti-virus 5.2.1
    sophos anti-virus 6.0.4
    sophos endpoint security *