Buffer Overflow Vulnerabilities in Sophos Anti-Virus Product
CVE-2006-6335
Currently unrated
Summary
Multiple buffer overflow vulnerabilities in the Sophos Anti-Virus scanning engine prior to version 2.40 permit attackers to execute arbitrary code remotely. An attacker could leverage a specially crafted SIT archive with a long, non-null-terminated filename to trigger a heap-based overflow in veex.dll. Additionally, a malicious CPIO archive with a similarly inappropriate filename length leads to a stack-based overflow in the same DLL. This exploitation underscores the importance of proper input validation to prevent malicious exploitation.
References
EPSS Score
12% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved