CVE-2007-1226
https://notcve.org/view.php?id=CVE-2007-1226
McAfee VirusScan for Mac (Virex) before 7.7 patch 1 has weak permissions (0666) for /Library/Application Support/Virex/VShieldExclude.txt, which allows local users to reconfigure Virex to skip scanning of arbitrary files. McAfee VirusScan para Mac (Virex) versiones anteriores a 7.7 patch 1 tiene permisos débiles (0666) para /Library/Application Support/Virex/VShieldExclude.txt, lo cual permite a usuarios locales reconfigurar Virex para saltar la comprobación de ficheros de su elección. • http://osvdb.org/33798 http://secunia.com/advisories/24337 http://securityreason.com/securityalert/2342 http://www.securityfocus.com/archive/1/461485/100/0/threaded http://www.securityfocus.com/bid/22744 http://www.securitytracker.com/id?1017707 http://www.vupen.com/english/advisories/2007/0777 https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=518722&sliceId=SAL_Public&command=show&forward=nonthreadedKC&kcId=518722 •
CVE-2007-1227 – McAfee VirusScan for Mac (Virex) 7.7 - Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2007-1227
VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary files via a symlink attack on /Library/Application Support/Virex/VShieldExclude.txt, as demonstrated by symlinking to the root crontab file to execute arbitrary commands. VShieldCheck en McAfee VirusScan para Mac (Virex) anterior a 7.7 patch 1 permite a usuarios locales cambiar los permisos de archivos de su elección mediante un ataque de enlace simbólico en /Library/Application Support/Virex/VShieldExclude.txt, como ha sido demostrado enlazando simbólicamente al archivo crontab del usuario root para ejecutar comandos de su elección. • https://www.exploit-db.com/exploits/3386 http://osvdb.org/33797 http://secunia.com/advisories/24337 http://securityreason.com/securityalert/2342 http://www.securityfocus.com/archive/1/461485/100/0/threaded http://www.securityfocus.com/bid/22744 http://www.securitytracker.com/id?1017707 http://www.vupen.com/english/advisories/2007/0777 https://exchange.xforce.ibmcloud.com/vulnerabilities/32729 https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=518722&sliceId=SAL_Public&command • CWE-264: Permissions, Privileges, and Access Controls •