First published: Thu Dec 14 2006(Updated: )
Untrusted search path vulnerability in McAfee VirusScan for Linux 4510e and earlier includes the current working directory in the DT_RPATH environment variable, which allows local users to load arbitrary ELF DSO libraries and execute arbitrary code by installing malicious libraries in that directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee VirusScan | <=4510e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6474 has been classified as a high severity vulnerability due to its potential for arbitrary code execution.
To fix CVE-2006-6474, upgrade to a version of McAfee VirusScan for Linux later than 4510e that does not include this vulnerability.
CVE-2006-6474 affects users of McAfee VirusScan for Linux version 4510e and earlier.
CVE-2006-6474 is an untrusted search path vulnerability that allows local users to execute arbitrary code.
CVE-2006-6474 is not remotely exploitable as it requires local access to the affected system.