libclamav/others.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 uses insecure permissions for temporary files that are created by the cli_gentempstream function in clamd/clamdscan, which might allow local users to read sensitive files.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2007-06-07T22:00:00
Updated: 2007-06-22T09:00:00
Reserved: 2007-06-04T00:00:00
Link: CVE-2007-3024
JSON object: View
NVD Information
Status : Analyzed
Published: 2007-06-07T22:30:00.000
Modified: 2008-09-05T21:24:38.610
Link: CVE-2007-3024
JSON object: View
Redhat Information
No data.
CWE