Back to search
CVE-2007-6595
Published: Dec 31, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
ClamAV 0.92 allows local users to overwrite arbitrary files via a symlink attack on (1) temporary files used by the cli_gentempfd function in libclamav/others.c or on (2) .ascii files used by sigtool, when utf16-decode is enabled.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
MDVSA-2008:088
vendor-advisory
x_refsource_MANDRIVA
1019148
vdb-entry
x_refsource_SECTRACK
clamantivirus-cligentempfd-symlink(39335)
vdb-entry
x_refsource_XF
3501
third-party-advisory
x_refsource_SREASON
31437
third-party-advisory
x_refsource_SECUNIA
29891
third-party-advisory
x_refsource_SECUNIA
28949
third-party-advisory
x_refsource_SECUNIA
DSA-1497
vendor-advisory
x_refsource_DEBIAN
27064
vdb-entry
x_refsource_BID
ADV-2008-0606
vdb-entry
x_refsource_VUPEN
GLSA-200808-07
vendor-advisory
x_refsource_GENTOO
clamantivirus-sigtool-file-overwrite(39339)
vdb-entry
x_refsource_XF
SUSE-SA:2008:024
vendor-advisory
x_refsource_SUSE
http://kolab.org/security/kolab-vendor-notice-19.txt
x_refsource_CONFIRM
20071229 TK53 Advisory #2: Multiple vulnerabilities in ClamAV
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now