Overview
McAfee VirusScan for Linux contains multiple vulnerabilities.
Description
McAfee VirusScan for Linux version 2.0.3 and prior is vulnerable to the following: CWE-200: Information Exposure - CVE-2016-8016 |
Impact
A remote unauthenticated attacker may be able to read limited subsets of files and logs on the system, execute arbitrary JavaScript code in the web interface, or execute arbitrary code on the system. |
Solution
Upgrade to a new product |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Temporal | 7.3 | E:POC/RL:OF/RC:C |
Environmental | 5.5 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Andrew Fasano for reporting these vulnerabilities to us.
This document was written by Garret Wassermann.
Other Information
CVE IDs: | CVE-2016-8016, CVE-2016-8017, CVE-2016-8018, CVE-2016-8019, CVE-2016-8020, CVE-2016-8021, CVE-2016-8022, CVE-2016-8023, CVE-2016-8024, CVE-2016-8025 |
Date Public: | 2016-12-09 |
Date First Published: | 2016-12-12 |
Date Last Updated: | 2016-12-13 20:37 UTC |
Document Revision: | 65 |