Untrusted Search Path Vulnerability in McAfee VirusScan for Linux
CVE-2006-6474

Currently unrated

Key Information:

Vendor

Mcafee

Status
Vendor
CVE Published:
14 December 2006

What is CVE-2006-6474?

The vulnerability in McAfee VirusScan for Linux arises from the inclusion of the current working directory in the DT_RPATH environment variable. This design flaw permits local users to load arbitrary ELF DSO libraries from maliciously crafted directories, potentially leading to unauthorized code execution on the affected system. By exploiting this weakness, an attacker can compromise the integrity of the system, paving the way for further malicious activities.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2006-6474 : Untrusted Search Path Vulnerability in McAfee VirusScan for Linux