CVE-2006-2427Anti-virus Clamav vulnerability

4 documents4 sources
Severity
7.2HIGHNVD
EPSS
0.0%
top 85.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateMay 1

Description

freshclam in (1) Clam Antivirus (ClamAV) 0.88 and (2) ClamXav 1.0.3h and earlier does not drop privileges before processing the config-file command line option, which allows local users to read portions of arbitrary files when an error message displays the first line of the target file.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-3ch5-6956-fx84: freshclam in (1) Clam Antivirus (ClamAV) 02022-05-01
CVEList
CVE-2006-2427: freshclam in (1) Clam Antivirus (ClamAV) 02006-05-17

📋Vendor Advisories

1
Debian
CVE-2006-2427: clamav - freshclam in (1) Clam Antivirus (ClamAV) 0.88 and (2) ClamXav 1.0.3h and earlier...2006
CVE-2006-2427 — Clam Anti-virus Clamav vulnerability | cvebase