CVE-2006-5645 describes a denial-of-service vulnerability affecting Sophos Anti-Virus and Endpoint Security products. Specifically, versions prior to 6.0.5 for Windows, 5.0.10 for Linux, and 4.11 for other platforms are susceptible when archive scanning is enabled. An unauthenticated remote attacker can trigger an infinite loop by providing a malformed RAR archive with zeroed head_size and pack_size fields in the Archive Header, leading to system unavailability. While a Proof-of-Concept exploit exists on ExploitDB, there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.04CPE matchmatch criteria | cpe:2.3:a:sophos:anti-virus:4.04:*:*:*:*:*:*:* | ||
4.05CPE matchmatch criteria | cpe:2.3:a:sophos:anti-virus:4.05:*:*:*:*:*:*:* | ||
4.5.3CPE matchmatch criteria | cpe:2.3:a:sophos:anti-virus:4.5.3:*:*:*:*:*:*:* | ||
4.5.4CPE matchmatch criteria | cpe:2.3:a:sophos:anti-virus:4.5.4:*:*:*:*:*:*:* | ||
4.5.11CPE matchmatch criteria | cpe:2.3:a:sophos:anti-virus:4.5.11:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.