ClamAV CVE-2006-2427 Local Security Vulnerability

ClamAV is prone to a local security vulnerability. freshclam in (1) Clam Antivirus (ClamAV) 0.88 and (2) ClamXav 1.0.3h and earlier does not drop privileges before processing the config-file command line option, which allows local users to read portions of arbitrary files when an error message displays the first line of the target file.


 

Privacy Statement
Copyright 2010, SecurityFocus