CVE-2012-6706

Source
https://nvd.nist.gov/vuln/detail/CVE-2012-6706
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2012-6706.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2012-6706
Related
Published
2017-06-22T13:29:00Z
Modified
2024-09-18T02:13:39.385391Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution. An integer overflow can be caused in DataSize+CurChannel. The result is a negative value of the "DestPos" variable, which allows the attacker to write out of bounds when setting Mem[DestPos].

References

Affected packages

Alpine:v3.10 / clamav

Package

Name
clamav
Purl
pkg:apk/alpine/clamav?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.99.4-r0

Affected versions

0.*

0.94.2-r0
0.94.2-r1
0.94.2-r2
0.95.1-r0
0.95.1-r1
0.95.2-r0
0.95.2-r1
0.95.3-r0
0.95.3-r1
0.96-r0
0.96.1-r0
0.96.2-r0
0.96.3-r0
0.96.4-r0
0.96.5-r0
0.97-r0
0.97-r1
0.97-r2
0.97-r3
0.97-r4
0.97.1-r0
0.97.2-r0
0.97.3-r0
0.97.3-r1
0.97.3-r2
0.97.3-r3
0.97.4-r0
0.97.4-r1
0.97.4-r2
0.97.5-r0
0.97.6-r0
0.97.6-r1
0.97.7-r0
0.97.8-r0
0.97.8-r1
0.97.8-r2
0.98-r0
0.98-r1
0.98.1-r0
0.98.1-r1
0.98.1-r2
0.98.3-r0
0.98.4-r0
0.98.4-r1
0.98.5-r0
0.98.6-r0
0.98.6-r1
0.98.6-r2
0.98.7-r0
0.98.7-r1
0.98.7-r2
0.99-r0
0.99-r1
0.99-r2
0.99-r3
0.99.1-r0
0.99.1-r1
0.99.1-r2
0.99.2-r0
0.99.2-r1
0.99.2-r2
0.99.2-r3
0.99.2-r4
0.99.2-r5
0.99.2-r6
0.99.3-r1
0.99.3-r2
0.99.3-r3

Alpine:v3.11 / clamav

Package

Name
clamav
Purl
pkg:apk/alpine/clamav?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.99.4-r0

Affected versions

0.*

0.94.2-r0
0.94.2-r1
0.94.2-r2
0.95.1-r0
0.95.1-r1
0.95.2-r0
0.95.2-r1
0.95.3-r0
0.95.3-r1
0.96-r0
0.96.1-r0
0.96.2-r0
0.96.3-r0
0.96.4-r0
0.96.5-r0
0.97-r0
0.97-r1
0.97-r2
0.97-r3
0.97-r4
0.97.1-r0
0.97.2-r0
0.97.3-r0
0.97.3-r1
0.97.3-r2
0.97.3-r3
0.97.4-r0
0.97.4-r1
0.97.4-r2
0.97.5-r0
0.97.6-r0
0.97.6-r1
0.97.7-r0
0.97.8-r0
0.97.8-r1
0.97.8-r2
0.98-r0
0.98-r1
0.98.1-r0
0.98.1-r1
0.98.1-r2
0.98.3-r0
0.98.4-r0
0.98.4-r1
0.98.5-r0
0.98.6-r0
0.98.6-r1
0.98.6-r2
0.98.7-r0
0.98.7-r1
0.98.7-r2
0.99-r0
0.99-r1
0.99-r2
0.99-r3
0.99.1-r0
0.99.1-r1
0.99.1-r2
0.99.2-r0
0.99.2-r1
0.99.2-r2
0.99.2-r3
0.99.2-r4
0.99.2-r5
0.99.2-r6
0.99.3-r1
0.99.3-r2
0.99.3-r3

Alpine:v3.12 / clamav

Package

Name
clamav
Purl
pkg:apk/alpine/clamav?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.99.4-r0

Affected versions

0.*

0.94.2-r0
0.94.2-r1
0.94.2-r2
0.95.1-r0
0.95.1-r1
0.95.2-r0
0.95.2-r1
0.95.3-r0
0.95.3-r1
0.96-r0
0.96.1-r0
0.96.2-r0
0.96.3-r0
0.96.4-r0
0.96.5-r0
0.97-r0
0.97-r1
0.97-r2
0.97-r3
0.97-r4
0.97.1-r0
0.97.2-r0
0.97.3-r0
0.97.3-r1
0.97.3-r2
0.97.3-r3
0.97.4-r0
0.97.4-r1
0.97.4-r2
0.97.5-r0
0.97.6-r0
0.97.6-r1
0.97.7-r0
0.97.8-r0
0.97.8-r1
0.97.8-r2
0.98-r0
0.98-r1
0.98.1-r0
0.98.1-r1
0.98.1-r2
0.98.3-r0
0.98.4-r0
0.98.4-r1
0.98.5-r0
0.98.6-r0
0.98.6-r1
0.98.6-r2
0.98.7-r0
0.98.7-r1
0.98.7-r2
0.99-r0
0.99-r1
0.99-r2
0.99-r3
0.99.1-r0
0.99.1-r1
0.99.1-r2
0.99.2-r0
0.99.2-r1
0.99.2-r2
0.99.2-r3
0.99.2-r4
0.99.2-r5
0.99.2-r6
0.99.3-r1
0.99.3-r2
0.99.3-r3

Alpine:v3.13 / clamav

Package

Name
clamav
Purl
pkg:apk/alpine/clamav?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.99.4-r0

Affected versions

0.*

0.94.2-r0
0.94.2-r1
0.94.2-r2
0.95.1-r0
0.95.1-r1
0.95.2-r0
0.95.2-r1
0.95.3-r0
0.95.3-r1
0.96-r0
0.96.1-r0
0.96.2-r0
0.96.3-r0
0.96.4-r0
0.96.5-r0
0.97-r0
0.97-r1
0.97-r2
0.97-r3
0.97-r4
0.97.1-r0
0.97.2-r0
0.97.3-r0
0.97.3-r1
0.97.3-r2
0.97.3-r3
0.97.4-r0
0.97.4-r1
0.97.4-r2
0.97.5-r0
0.97.6-r0
0.97.6-r1
0.97.7-r0
0.97.8-r0
0.97.8-r1
0.97.8-r2
0.98-r0
0.98-r1
0.98.1-r0
0.98.1-r1
0.98.1-r2
0.98.3-r0
0.98.4-r0
0.98.4-r1
0.98.5-r0
0.98.6-r0
0.98.6-r1
0.98.6-r2
0.98.7-r0
0.98.7-r1
0.98.7-r2
0.99-r0
0.99-r1
0.99-r2
0.99-r3
0.99.1-r0
0.99.1-r1
0.99.1-r2
0.99.2-r0
0.99.2-r1
0.99.2-r2
0.99.2-r3
0.99.2-r4
0.99.2-r5
0.99.2-r6
0.99.3-r1
0.99.3-r2
0.99.3-r3

Alpine:v3.8 / clamav

Package

Name
clamav
Purl
pkg:apk/alpine/clamav?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.99.4-r0

Affected versions

0.*

0.94.2-r0
0.94.2-r1
0.94.2-r2
0.95.1-r0
0.95.1-r1
0.95.2-r0
0.95.2-r1
0.95.3-r0
0.95.3-r1
0.96-r0
0.96.1-r0
0.96.2-r0
0.96.3-r0
0.96.4-r0
0.96.5-r0
0.97-r0
0.97-r1
0.97-r2
0.97-r3
0.97-r4
0.97.1-r0
0.97.2-r0
0.97.3-r0
0.97.3-r1
0.97.3-r2
0.97.3-r3
0.97.4-r0
0.97.4-r1
0.97.4-r2
0.97.5-r0
0.97.6-r0
0.97.6-r1
0.97.7-r0
0.97.8-r0
0.97.8-r1
0.97.8-r2
0.98-r0
0.98-r1
0.98.1-r0
0.98.1-r1
0.98.1-r2
0.98.3-r0
0.98.4-r0
0.98.4-r1
0.98.5-r0
0.98.6-r0
0.98.6-r1
0.98.6-r2
0.98.7-r0
0.98.7-r1
0.98.7-r2
0.99-r0
0.99-r1
0.99-r2
0.99-r3
0.99.1-r0
0.99.1-r1
0.99.1-r2
0.99.2-r0
0.99.2-r1
0.99.2-r2
0.99.2-r3
0.99.2-r4
0.99.2-r5
0.99.2-r6
0.99.3-r1
0.99.3-r2
0.99.3-r3

Alpine:v3.9 / clamav

Package

Name
clamav
Purl
pkg:apk/alpine/clamav?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.99.4-r0

Affected versions

0.*

0.94.2-r0
0.94.2-r1
0.94.2-r2
0.95.1-r0
0.95.1-r1
0.95.2-r0
0.95.2-r1
0.95.3-r0
0.95.3-r1
0.96-r0
0.96.1-r0
0.96.2-r0
0.96.3-r0
0.96.4-r0
0.96.5-r0
0.97-r0
0.97-r1
0.97-r2
0.97-r3
0.97-r4
0.97.1-r0
0.97.2-r0
0.97.3-r0
0.97.3-r1
0.97.3-r2
0.97.3-r3
0.97.4-r0
0.97.4-r1
0.97.4-r2
0.97.5-r0
0.97.6-r0
0.97.6-r1
0.97.7-r0
0.97.8-r0
0.97.8-r1
0.97.8-r2
0.98-r0
0.98-r1
0.98.1-r0
0.98.1-r1
0.98.1-r2
0.98.3-r0
0.98.4-r0
0.98.4-r1
0.98.5-r0
0.98.6-r0
0.98.6-r1
0.98.6-r2
0.98.7-r0
0.98.7-r1
0.98.7-r2
0.99-r0
0.99-r1
0.99-r2
0.99-r3
0.99.1-r0
0.99.1-r1
0.99.1-r2
0.99.2-r0
0.99.2-r1
0.99.2-r2
0.99.2-r3
0.99.2-r4
0.99.2-r5
0.99.2-r6
0.99.3-r1
0.99.3-r2
0.99.3-r3

Debian:11 / libclamunrar

Package

Name
libclamunrar
Purl
pkg:deb/debian/libclamunrar?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.99-4

Affected versions

0.*

0.95.1-1
0.95.2-1
0.95.3-1~volatile1
0.95.3-1
0.96-1
0.96-2~volatile1
0.96-2
0.96.4-1~volatile1
0.96.4-1
0.98.1-1
0.98.5-1
0.99-1
0.99-2
0.99-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / libclamunrar

Package

Name
libclamunrar
Purl
pkg:deb/debian/libclamunrar?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.99-4

Affected versions

0.*

0.95.1-1
0.95.2-1
0.95.3-1~volatile1
0.95.3-1
0.96-1
0.96-2~volatile1
0.96-2
0.96.4-1~volatile1
0.96.4-1
0.98.1-1
0.98.5-1
0.99-1
0.99-2
0.99-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / libclamunrar

Package

Name
libclamunrar
Purl
pkg:deb/debian/libclamunrar?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.99-4

Affected versions

0.*

0.95.1-1
0.95.2-1
0.95.3-1~volatile1
0.95.3-1
0.96-1
0.96-2~volatile1
0.96-2
0.96.4-1~volatile1
0.96.4-1
0.98.1-1
0.98.5-1
0.99-1
0.99-2
0.99-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / unrar-nonfree

Package

Name
unrar-nonfree
Purl
pkg:deb/debian/unrar-nonfree?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:5.5.5-1

Affected versions

3.*

3.3.6-2
3.3.6-2.0.1
3.4.3-1

1:3.*

1:3.5.2-0.1
1:3.5.2-0.2
1:3.5.4-0.1
1:3.5.4-1
1:3.5.4-1.1
1:3.7.2-1
1:3.7.3-1
1:3.7.3-1.1
1:3.7.8-1
1:3.7.8-2
1:3.8.2-1
1:3.8.4-1
1:3.8.5-1
1:3.8.5-2
1:3.9.3-1
1:3.9.5-1
1:3.9.6-1
1:3.9.7-1
1:3.9.9-1
1:3.9.10-1

1:4.*

1:4.0.2-1
1:4.0.3-1
1:4.1.4-1
1:4.2.4-0.1
1:4.2.4-0.2
1:4.2.4-0.3

1:5.*

1:5.0.10-1
1:5.2.5-1
1:5.2.7-0.1
1:5.3.2-1
1:5.4.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / unrar-nonfree

Package

Name
unrar-nonfree
Purl
pkg:deb/debian/unrar-nonfree?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:5.5.5-1

Affected versions

3.*

3.3.6-2
3.3.6-2.0.1
3.4.3-1

1:3.*

1:3.5.2-0.1
1:3.5.2-0.2
1:3.5.4-0.1
1:3.5.4-1
1:3.5.4-1.1
1:3.7.2-1
1:3.7.3-1
1:3.7.3-1.1
1:3.7.8-1
1:3.7.8-2
1:3.8.2-1
1:3.8.4-1
1:3.8.5-1
1:3.8.5-2
1:3.9.3-1
1:3.9.5-1
1:3.9.6-1
1:3.9.7-1
1:3.9.9-1
1:3.9.10-1

1:4.*

1:4.0.2-1
1:4.0.3-1
1:4.1.4-1
1:4.2.4-0.1
1:4.2.4-0.2
1:4.2.4-0.3

1:5.*

1:5.0.10-1
1:5.2.5-1
1:5.2.7-0.1
1:5.3.2-1
1:5.4.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / unrar-nonfree

Package

Name
unrar-nonfree
Purl
pkg:deb/debian/unrar-nonfree?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:5.5.5-1

Affected versions

3.*

3.3.6-2
3.3.6-2.0.1
3.4.3-1

1:3.*

1:3.5.2-0.1
1:3.5.2-0.2
1:3.5.4-0.1
1:3.5.4-1
1:3.5.4-1.1
1:3.7.2-1
1:3.7.3-1
1:3.7.3-1.1
1:3.7.8-1
1:3.7.8-2
1:3.8.2-1
1:3.8.4-1
1:3.8.5-1
1:3.8.5-2
1:3.9.3-1
1:3.9.5-1
1:3.9.6-1
1:3.9.7-1
1:3.9.9-1
1:3.9.10-1

1:4.*

1:4.0.2-1
1:4.0.3-1
1:4.1.4-1
1:4.2.4-0.1
1:4.2.4-0.2
1:4.2.4-0.3

1:5.*

1:5.0.10-1
1:5.2.5-1
1:5.2.7-0.1
1:5.3.2-1
1:5.4.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}