CVE-2006-1125: Medium severity Grisoft AVG Antivirus vulnerability
Published Mar 9, 2006
·Updated
Grisoft AVG Free 7.1, and other versions including 7.0.308, sets Everyone/Full Control permissions for certain update files including (1) updvers.cfg, (2) incavi.avm, and (3) unspecified drivers, which might allow local users to gain privileges.
Affected Software
4 affected components
Grisoft AVG Antivirus=7.0
Grisoft AVG Antivirus=7.0.251
Grisoft AVG Antivirus=7.0.323
Grisoft AVG Antivirus=7.1.308
Remediation
Patch Available
Patch Available
Event History
Mar 9, 2006
CVE Published
09:02 PM
Mar 10, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1125?
CVE-2006-1125 has a medium severity rating due to the potential for local privilege escalation.
2
How do I fix CVE-2006-1125?
To mitigate CVE-2006-1125, restrict permissions on the affected update files to limit access.
3
Which versions of AVG Antivirus are affected by CVE-2006-1125?
CVE-2006-1125 affects AVG Antivirus versions 7.0.308, 7.0.251, 7.0.323, and 7.1.308.
4
What consequence can result from the vulnerability described in CVE-2006-1125?
The consequence of CVE-2006-1125 could allow local users to gain unauthorized privileges on the system.
5
Is there a workaround for CVE-2006-1125 before a permanent fix is applied?
Yes, a temporary workaround for CVE-2006-1125 includes changing the file permission settings to prevent unauthorized access.