First published: Tue Aug 16 2005(Updated: )
Kaspersky Anti-Virus for Unix/Linux File Servers 5.0-5 uses world-writable permissions for the (1) log and (2) license directory, which allows local users to delete log files, append to arbitrary files via a symlink attack on kavmonitor.log, or delete license keys and prevent keepup2date from properly executing.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kaspersky Anti-Virus | =5.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2582 is considered a medium severity vulnerability due to its local privilege escalation risks.
To fix CVE-2005-2582, adjust the permissions of the log and license directories to prevent unauthorized access.
The risks include the potential for local users to delete log files and license keys, which can disrupt the operation of Kaspersky Anti-Virus.
CVE-2005-2582 affects Kaspersky Anti-Virus for Unix/Linux File Servers version 5.0-5.0.5.
CVE-2005-2582 cannot be exploited remotely as it requires local access to the affected system.