CVE-2006-6406
clamav
EPSS 2.4%
Description
Clam AntiVirus (ClamAV) 0.88.6 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.
How to fix CVE-2006-6406
To remediate CVE-2006-6406, upgrade the affected package to a fixed version below.
- Debian/clamav—upgrade to 0.88.7-1 or later
- Debian/clamav—upgrade to 0.84-2.sarge.13 or later
Is CVE-2006-6406 being exploited?
Low — EPSS is 2.4%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.88.7-1
- from 0, < 0.84-2.sarge.13