Kaspersky Anti-Virus For Unix Local Insecure Default Permission Vulnerabilities
BID:14554
Info
Kaspersky Anti-Virus For Unix Local Insecure Default Permission Vulnerabilities
| Bugtraq ID: | 14554 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 12 2005 12:00AM |
| Updated: | Aug 12 2005 12:00AM |
| Credit: | "Dr. Peter Bieringer" <[email protected]> disclosed these vulnerabilities. |
| Vulnerable: |
Kaspersky Labs Kaspersky Antivirus for Linux Servers 5.5 |
| Not Vulnerable: | |
Discussion
Kaspersky Anti-Virus For Unix Local Insecure Default Permission Vulnerabilities
Kaspersky Anti-Virus for Unix File Servers is susceptible to two local insecure default permission vulnerabilities. These issues are due to the application failing to secure newly created directories upon installation.
The first insecure directory is used by the 'kavmonitor' binary to log actions of the anti-virus scanner. Attackers may exploit this vulnerability to delete or alter log files to obscure attack traces, or use symbolic links to cause the affected utility to overwrite arbitrary files with superuser privileges.
The second insecure directory is used to hold licensing data for the product. Attackers may delete or alter the license key files, causing the 'keepup2date' utility to fail. This utility is used by the application to keep the anti-virus signatures updated.
These vulnerabilities are reported in version 5.5-2 of Kaspersky Anti-Virus for Unix. Other versions may also be affected.
Kaspersky Anti-Virus for Unix File Servers is susceptible to two local insecure default permission vulnerabilities. These issues are due to the application failing to secure newly created directories upon installation.
The first insecure directory is used by the 'kavmonitor' binary to log actions of the anti-virus scanner. Attackers may exploit this vulnerability to delete or alter log files to obscure attack traces, or use symbolic links to cause the affected utility to overwrite arbitrary files with superuser privileges.
The second insecure directory is used to hold licensing data for the product. Attackers may delete or alter the license key files, causing the 'keepup2date' utility to fail. This utility is used by the application to keep the anti-virus signatures updated.
These vulnerabilities are reported in version 5.5-2 of Kaspersky Anti-Virus for Unix. Other versions may also be affected.
Exploit / POC
Kaspersky Anti-Virus For Unix Local Insecure Default Permission Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
Kaspersky Anti-Virus For Unix Local Insecure Default Permission Vulnerabilities
Solution:
The reporter of this issue states that these issues have been fixed in version 5.5-3 of Kaspersky Anti-Virus For Unix. This has not been confirmed by Symantec. Users of affected packages are urged to contact the vendor for further information on obtaining fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The reporter of this issue states that these issues have been fixed in version 5.5-3 of Kaspersky Anti-Virus For Unix. This has not been confirmed by Symantec. Users of affected packages are urged to contact the vendor for further information on obtaining fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Kaspersky Anti-Virus For Unix Local Insecure Default Permission Vulnerabilities
References:
References:
- Kaspersky Antivirus Homepage (Kaspersky Labs)
- Insecure directory permissions of default installation of Kaspersky Anti-Virus ("Dr. Peter Bieringer"
)