Title : Kaspersky AntiVirus Log Directory Insecure Permissions Vulnerability VUPEN ID : VUPEN/ADV-2005-1410 CVE ID : CVE-2005-2582 CWE ID : CWE-
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2005-08-15
Technical Description
A vulnerability was identified in Kaspersky AntiVirus for Unix, which could be exploited by local attackers to gain elevated privileges. The problem is caused due to log files being created in the "/var/log/kav/5.5/kav4unix/" directory with insecure permissions, which could be exploited by local users to create or overwrite arbitrary files with "root" privileges via symlink attacks.