MEDIUM · 4.6

CVE-2006-6474

Untrusted search path vulnerability in McAfee VirusScan for Linux 4510e and earlier includes the current working directory in the DT_RPATH environment variable, which allows local users to load arbitr...

Vulnerability Description

Untrusted search path vulnerability in McAfee VirusScan for Linux 4510e and earlier includes the current working directory in the DT_RPATH environment variable, which allows local users to load arbitrary ELF DSO libraries and execute arbitrary code by installing malicious libraries in that directory.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
McafeeVirusscan<= 4510e

References

FAQ

What is CVE-2006-6474?

CVE-2006-6474 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Untrusted search path vulnerability in McAfee VirusScan for Linux 4510e and earlier includes the current working directory in the DT_RPATH environment variable, which allows local users to load arbitr...

How severe is CVE-2006-6474?

CVE-2006-6474 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-6474?

Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Virusscan.