Executive Summary

Summary
Title ClamAV vulnerability
Informations
Name USN-770-1 First vendor Publication 2009-05-04
Vendor Ubuntu Last vendor Modification 2009-05-04
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:S/C:C/I:C/A:C)
Cvss Base Score 6.8 Attack Range Local
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 3.1 Authentication Requires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

A security issue affects the following Ubuntu releases:

Ubuntu 9.04

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

Ubuntu 9.04:
clamav-milter 0.95.1+dfsg-1ubuntu1.2

In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

A flaw was discovered in the clamav-milter initscript which caused the ownership of the current working directory to be changed to the 'clamav' user. This update attempts to repair the incorrect ownership for standard system directories, but it is recommended that the following command be performed to report any other directories that may be affected:

$ sudo find -H / -type d -user clamav \! -group clamav 2>/dev/null

Systems configured to run clamav as a user other than the default 'clamav' user will need to adjust the above command accordingly.

Original Source

Url : http://www.ubuntu.com/usn/USN-770-1

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-264 Permissions, Privileges, and Access Controls

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 1

OpenVAS Exploits

Date Description
2009-06-05 Name : Ubuntu USN-770-1 (clamav)
File : nvt/ubuntu_770_1.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
54524 clamav-milter clamav-milter.init on Ubuntu Directory Permission Weakness Loca...

Nessus® Vulnerability Scanner

Date Description
2009-05-05 Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-770-1.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2014-02-17 12:05:56
  • Multiple Updates