Back to search
CVE-2007-3024
Published: Jun 7, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
libclamav/others.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 uses insecure permissions for temporary files that are created by the cli_gentempstream function in clamd/clamdscan, which might allow local users to read sensitive files.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
25796
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2007:033
vendor-advisory
x_refsource_SUSE
25525
third-party-advisory
x_refsource_SECUNIA
25523
third-party-advisory
x_refsource_SECUNIA
DSA-1320
vendor-advisory
x_refsource_DEBIAN
http://kolab.org/security/kolab-vendor-notice-15.txt
x_refsource_CONFIRM
25688
third-party-advisory
x_refsource_SECUNIA
[Clamav-announce] 20070530 announcing ClamAV 0.90.3
mailing-list
x_refsource_MLIST
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=517
x_refsource_CONFIRM
24358
vdb-entry
x_refsource_BID
http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog
x_refsource_CONFIRM
GLSA-200706-05
vendor-advisory
x_refsource_GENTOO
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now