First published: Wed Dec 12 2018(Updated: )
Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivileged User to introduce custom paths during agent installation in Linux via unspecified vectors.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Agent | >=5.0.0<=5.0.6 | |
Mcafee Agent | =5.5.0 | |
Mcafee Agent | =5.5.1 |
McAfee highly recommends that all customers upgrade to McAfee Agent 5.6.0.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-6706 is high with a severity value of 7.5.
CVE-2018-6706 affects non-Windows McAfee Agent versions 5.0.0 through 5.0.6, 5.5.0, and 5.5.1.
CVE-2018-6706 is caused by insecure handling of temporary files in non-Windows McAfee Agent, allowing an Unprivileged User to introduce custom paths during agent installation in Linux.
Yes, McAfee has released a fix for this vulnerability. Please refer to the McAfee knowledge base article for more information.
You can find more information about CVE-2018-6706 on the SecurityFocus and McAfee websites.