CVE-2006-0232: Medium severity Symantec AntiVirus Scan Engine vulnerability
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0232?
CVE-2006-0232 has a moderate severity level due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2006-0232?
To fix CVE-2006-0232, update the Symantec Scan Engine to version 5.1.0.7 or later, which addresses the access control issue.
What versions of Symantec Scan Engine are affected by CVE-2006-0232?
CVE-2006-0232 affects Symantec Scan Engine version 5.0.0.24 and possibly earlier versions prior to 5.1.0.7.
What kind of files are exposed due to CVE-2006-0232?
CVE-2006-0232 exposes sensitive log and virus definition files that can be accessed by remote attackers.
Can remote attackers exploit CVE-2006-0232 easily?
Yes, remote attackers can exploit CVE-2006-0232 easily by making direct requests to the vulnerable web server.