First published: Wed Nov 16 2005(Updated: )
suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
f-secure f-secure anti-virus | ||
F-Secure Internet Gatekeeper for Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3546 is considered a moderate severity vulnerability due to its potential to allow local users to gain elevated privileges.
To fix CVE-2005-3546, update the F-Secure Internet Gatekeeper or Anti-Virus Linux Gateway to a version that does not install suid.cgi scripts with world-executable permissions.
CVE-2005-3546 affects users running F-Secure Internet Gatekeeper for Linux versions prior to 2.15.484 and F-Secure Anti-Virus Linux Gateway versions prior to 2.16.
The consequences of CVE-2005-3546 include the risk of local users executing scripts with elevated privileges, potentially compromising system integrity.
Yes, patches have been provided in the updated versions of the F-Secure products that address the vulnerability in CVE-2005-3546.