First published: Mon Dec 18 2006(Updated: )
Soft4Ever Look 'n' Stop (LnS) 2.05p2 before 20061215 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AVG Antivirus Plus Firewall | =7.5.431 | |
Comodo Firewall Pro | =2.3.6.81 | |
Filseclab Personal Firewall | =3.0.8686 | |
Infoprocess Antihook | =3.0.23 | |
Look 'n' Stop Firewall | =2.05p2 | |
Sygate Technologies | =5.6.2808 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-6622 is considered to be high due to its potential for local users to bypass security controls.
To fix CVE-2006-6622, upgrade Soft4Ever Look 'n' Stop to version 2.05p2 or later, or apply any available patches that address this vulnerability.
CVE-2006-6622 affects processes identified by Soft4Ever Look 'n' Stop and can be exploited by spoofing fields in the Process Environment Block.
Local users on systems running affected versions of Soft4Ever Look 'n' Stop can exploit CVE-2006-6622, compromising the firewall controls.
CVE-2006-6622 is a local vulnerability, requiring access to the affected system to exploit.