>> ClamXav "freshclam" Insecure Permissions Information Disclosure Vulnerability
Title : ClamXav "freshclam" Insecure Permissions Information Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2006-1807 CVE ID : CVE-2006-2427
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-05-15
Technical Description
A vulnerability has been identified in ClamXav, which may be exploited by malicious users to gain knowledge of sensitive information. This flaw is due to insecure permissions being set on the "freshclam" utility during installation, which could be exploited by local attackers to disclose, in error messages, parts of certain files (e.g. "/etc/shadow") by maipulating the "--config-file" argument.