First published: Thu Apr 06 2006(Updated: )
The "restore to" selection in the "quarantine a file" capability of ESET NOD32 before 2.51.26 allows a restore to any directory that permits read access by the invoking user, which allows local users to create new files despite write-access directory permissions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ESET NOD32 Antivirus | =1.0.11 | |
ESET NOD32 Antivirus | =1.0.12 | |
ESET NOD32 Antivirus | =1.0.13 | |
ESET NOD32 Antivirus | =2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1649 is classified as a medium severity vulnerability.
To fix CVE-2006-1649, update ESET NOD32 Antivirus to version 2.51.26 or newer.
CVE-2006-1649 affects ESET NOD32 Antivirus versions 1.0.11, 1.0.12, 1.0.13, and 2.5.
CVE-2006-1649 is a local privilege escalation vulnerability.
Yes, local users can exploit CVE-2006-1649 to create new files in directories where they have read access.