PT-2006-7083 · Mcafee · Mcafee Virusscan For Linux

Jakub Moc

·

Published

2006-12-14

·

Updated

2017-07-29

·

CVE-2006-6474

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions McAfee VirusScan for Linux versions 4510e and earlier
Description The issue concerns an untrusted search path vulnerability. It includes the current working directory in the DT RPATH environment variable, allowing local users to load arbitrary ELF DSO libraries and execute arbitrary code by installing malicious libraries in that directory.
Recommendations For McAfee VirusScan for Linux versions 4510e and earlier, consider restricting access to the DT RPATH environment variable to prevent local users from loading arbitrary ELF DSO libraries until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6474

Affected Products

Mcafee Virusscan For Linux