CVE-2006-3786: Low severity symantec pcanywhere vulnerability
Symantec pcAnywhere 12.5 uses weak integrity protection for .cif (aka caller or CallerID) files, which allows local users to generate a custom .cif file and modify the superuser flag.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3786?
CVE-2006-3786 is classified as a medium severity vulnerability due to the potential for local users to exploit weak integrity protection.
How do I fix CVE-2006-3786?
To fix CVE-2006-3786, update to a version of Symantec pcAnywhere that does not use weak integrity protection for .cif files.
Who is affected by CVE-2006-3786?
CVE-2006-3786 specifically affects users of Symantec pcAnywhere version 12.5.
What impact does CVE-2006-3786 have on the system?
CVE-2006-3786 can allow local users to create custom .cif files and modify the superuser flag, potentially leading to unauthorized access.
Is there a workaround for CVE-2006-3786?
There are no known workarounds for CVE-2006-3786 other than applying the appropriate software update.