Vulnerability Name: | CVE-2006-2427 (CCN-26453) | ||||||||
Assigned: | 2006-05-14 | ||||||||
Published: | 2006-05-14 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | freshclam in (1) Clam Antivirus (ClamAV) 0.88 and (2) ClamXav 1.0.3h and earlier does not drop privileges before processing the config-file command line option, which allows local users to read portions of arbitrary files when an error message displays the first line of the target file. | ||||||||
CVSS v3 Severity: | 8.2 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sun May 14 2006 - 20:15:53 CDT DMA[2006-0514a] - 'ClamAV freshclam incorrect privilege drop' Source: MITRE Type: CNA CVE-2006-2427 Source: CCN Type: SA20085 ClamXav freshclam suid Permissions Security Issue Source: SECUNIA Type: Vendor Advisory 20085 Source: SREASON Type: UNKNOWN 912 Source: CCN Type: SECTRACK ID: 1016086 Clam AntiVirus `freshclam` May Let Local Users Access Files With Elevated Privileges Source: SECTRACK Type: Exploit 1016086 Source: CCN Type: Digital Munition Advisory DMA[2006-0514a] ClamAV freshclam incorrect privilege drop Source: MISC Type: Broken Link http://www.digitalmunition.com/DMA[2006-0514a].txt Source: CCN Type: ClamXav Web site ClamXav Source: CCN Type: OSVDB ID: 25520 Clam AntiVirus freshclam --config-file Arbitrary Privileged File Access Source: BUGTRAQ Type: UNKNOWN 20060515 DMA[2006-0514a] - 'ClamAV freshclam incorrect privilege drop' Source: VUPEN Type: UNKNOWN ADV-2006-1807 Source: XF Type: UNKNOWN clamxav-freshclam-insecure-privileges(26453) Source: XF Type: UNKNOWN clamxav-freshclam-insecure-privileges(26453) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |