CVE-2007-6595: Low severity Clam Anti-Virus clamav vulnerability
Published Dec 31, 2007
·Updated
ClamAV 0.92 allows local users to overwrite arbitrary files via a symlink attack on (1) temporary files used by the cligentempfd function in libclamav/others.c or on (2) .ascii files used by sigtool, when utf16-decode is enabled.
Affected Software
1 affected component
Clam Anti-Virus clamav=0.92
Event History
Dec 31, 2007
CVE Published
07:46 PM
Jan 1, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6595?
CVE-2007-6595 is classified as a medium severity vulnerability allowing local users to exploit a symlink attack.
2
How do I fix CVE-2007-6595?
To fix CVE-2007-6595, upgrade ClamAV to a version later than 0.92 that addresses this vulnerability.
3
What types of files are affected by CVE-2007-6595?
CVE-2007-6595 affects temporary files created by the cli_gentempfd function and .ascii files used by sigtool.
4
Who is vulnerable to CVE-2007-6595?
Local users on systems running ClamAV version 0.92 are vulnerable to CVE-2007-6595.
5
What can an attacker achieve with CVE-2007-6595?
An attacker can overwrite arbitrary files on the system due to the symlink vulnerability in CVE-2007-6595.