Buffer Overflow Vulnerabilities in Sophos Anti-Virus Product
CVE-2006-6335

Currently unrated

Key Information:

Vendor
Sophos
Vendor
CVE Published:
12 December 2006

Summary

Multiple buffer overflow vulnerabilities in the Sophos Anti-Virus scanning engine prior to version 2.40 permit attackers to execute arbitrary code remotely. An attacker could leverage a specially crafted SIT archive with a long, non-null-terminated filename to trigger a heap-based overflow in veex.dll. Additionally, a malicious CPIO archive with a similarly inappropriate filename length leads to a stack-based overflow in the same DLL. This exploitation underscores the importance of proper input validation to prevent malicious exploitation.

References

EPSS Score

12% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.