First published: Mon Jul 24 2006(Updated: )
Symantec pcAnywhere 12.5 uses weak integrity protection for .cif (aka caller or CallerID) files, which allows local users to generate a custom .cif file and modify the superuser flag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec pcAnywhere | =12.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3786 is classified as a medium severity vulnerability due to the potential for local users to exploit weak integrity protection.
To fix CVE-2006-3786, update to a version of Symantec pcAnywhere that does not use weak integrity protection for .cif files.
CVE-2006-3786 specifically affects users of Symantec pcAnywhere version 12.5.
CVE-2006-3786 can allow local users to create custom .cif files and modify the superuser flag, potentially leading to unauthorized access.
There are no known workarounds for CVE-2006-3786 other than applying the appropriate software update.