漏洞信息详情
McAfee VirusScan Virex "VShieldExclude.txt" 不安全文件创建和扫描绕过漏洞
漏洞简介
Mac (Virex) McAfee VirusScan 7.7 patch 1之前的版本为/Library/ApplicationSupport/Virex/VShieldExclude.txt使用弱许可(0666),这使得本地用户可以重新配置Virex,以便跳过对任意文件的扫描。
漏洞公告
参考网址
来源: VUPEN 名称: ADV-2007-0777 链接:http://www.frsirt.com/english/advisories/2007/0777 来源: SECUNIA 名称: 24337 链接:http://secunia.com/advisories/24337 来源: knowledge.mcafee.com 链接:https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=518722&sliceId=SAL_Public&command=show&forward=nonthreadedKC&kcId=518722 来源: SECTRACK 名称: 1017707 链接:http://www.securitytracker.com/id?1017707 来源: BID 名称: 22744 链接:http://www.securityfocus.com/bid/22744 来源: BUGTRAQ 名称: 20070227 [NETRAGARD-20070220 SECURITY ADVISORY] [McAfee VirusScan for Mac (Virex) Local root exploit and Scan Bypass] 链接:http://www.securityfocus.com/archive/1/archive/1/461485/100/0/threaded 来源: OSVDB 名称: 33798 链接:http://osvdb.org/33798 来源: SREASON 名称: 2342 链接:http://securityreason.com/securityalert/2342
受影响实体
- Mcafee Virex:7.7:Macintosh<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...