PT-2006-7083 · Mcafee · Mcafee Virusscan For Linux

Jakub Moc

·

Publicado

2006-12-14

·

Atualizado

2017-07-29

·

CVE-2006-6474

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions McAfee VirusScan for Linux versions 4510e and earlier
Description The issue concerns an untrusted search path vulnerability. It includes the current working directory in the DT RPATH environment variable, allowing local users to load arbitrary ELF DSO libraries and execute arbitrary code by installing malicious libraries in that directory.
Recommendations For McAfee VirusScan for Linux versions 4510e and earlier, consider restricting access to the DT RPATH environment variable to prevent local users from loading arbitrary ELF DSO libraries until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6474

Produtos afetados

Mcafee Virusscan For Linux