First published: Thu Mar 09 2006(Updated: )
Grisoft AVG Free 7.1, and other versions including 7.0.308, sets Everyone/Full Control permissions for certain update files including (1) upd_vers.cfg, (2) incavi.avm, and (3) unspecified drivers, which might allow local users to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AVG Antivirus Plus Firewall | =7.0 | |
AVG Antivirus Plus Firewall | =7.0.251 | |
AVG Antivirus Plus Firewall | =7.0.323 | |
AVG Antivirus Plus Firewall | =7.1.308 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1125 has a medium severity rating due to the potential for local privilege escalation.
To mitigate CVE-2006-1125, restrict permissions on the affected update files to limit access.
CVE-2006-1125 affects AVG Antivirus versions 7.0.308, 7.0.251, 7.0.323, and 7.1.308.
The consequence of CVE-2006-1125 could allow local users to gain unauthorized privileges on the system.
Yes, a temporary workaround for CVE-2006-1125 includes changing the file permission settings to prevent unauthorized access.