CVE Database
/

CVE-2006-2427

Back to search

CVE-2006-2427

Published: May 17, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

freshclam in (1) Clam Antivirus (ClamAV) 0.88 and (2) ClamXav 1.0.3h and earlier does not drop privileges before processing the config-file command line option, which allows local users to read portions of arbitrary files when an error message displays the first line of the target file.

VendorProductVersions

n/a

n/a

affected
n/a

References

1016086
vdb-entry
x_refsource_SECTRACK
ADV-2006-1807
vdb-entry
x_refsource_VUPEN
20085
third-party-advisory
x_refsource_SECUNIA
912
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now