Untrusted search path vulnerability in McAfee VirusScan for Linux 4510e and earlier includes the current working directory in the DT_RPATH environment variable, which allows local users to load arbitrary ELF DSO libraries and execute arbitrary code by installing malicious libraries in that directory.
References
Configurations
History
21 Nov 2024, 00:22
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/23278 - | |
References | () http://secunia.com/advisories/23429 - | |
References | () http://security.gentoo.org/glsa/glsa-200612-15.xml - | |
References | () http://securitytracker.com/id?1017385 - | |
References | () http://www.securityfocus.com/bid/21592 - | |
References | () http://www.vupen.com/english/advisories/2006/5023 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/30898 - |
Information
Published : 2006-12-14 20:28
Updated : 2024-11-21 00:22
NVD link : CVE-2006-6474
Mitre link : CVE-2006-6474
CVE.ORG link : CVE-2006-6474
JSON object : View
Products Affected
mcafee
- virusscan
CWE