CVE-2006-1649: High severity eset software nod32 antivirus vulnerability
Published Apr 6, 2006
·Updated
The "restore to" selection in the "quarantine a file" capability of ESET NOD32 before 2.51.26 allows a restore to any directory that permits read access by the invoking user, which allows local users to create new files despite write-access directory permissions.
Affected Software
4 affected components
Eset Software Nod32 Antivirus=1.0.11
Eset Software Nod32 Antivirus=1.0.12
Eset Software Nod32 Antivirus=2.5
Eset Software Nod32 Antivirus=1.0.13
Remediation
Patch Available
Event History
Apr 6, 2006
CVE Published
10:04 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1649?
CVE-2006-1649 is classified as a medium severity vulnerability.
2
How do I fix CVE-2006-1649?
To fix CVE-2006-1649, update ESET NOD32 Antivirus to version 2.51.26 or newer.
3
What systems are affected by CVE-2006-1649?
CVE-2006-1649 affects ESET NOD32 Antivirus versions 1.0.11, 1.0.12, 1.0.13, and 2.5.
4
What type of vulnerability is CVE-2006-1649?
CVE-2006-1649 is a local privilege escalation vulnerability.
5
Can local users exploit CVE-2006-1649?
Yes, local users can exploit CVE-2006-1649 to create new files in directories where they have read access.