PT-2006-7083 · Mcafee · Mcafee Virusscan For Linux
Jakub Moc
·
Published
2006-12-14
·
Updated
2017-07-29
·
CVE-2006-6474
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
McAfee VirusScan for Linux versions 4510e and earlier
Description
The issue concerns an untrusted search path vulnerability. It includes the current working directory in the DT RPATH environment variable, allowing local users to load arbitrary ELF DSO libraries and execute arbitrary code by installing malicious libraries in that directory.
Recommendations
For McAfee VirusScan for Linux versions 4510e and earlier, consider restricting access to the DT RPATH environment variable to prevent local users from loading arbitrary ELF DSO libraries until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcafee Virusscan For Linux