The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.
2004-04-15T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv3.1: 7.0 (HIGH)
AV:L/AC:H/Au:N/C:P/I:P/A:P
1.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | symantec | antivirus_scan_engine | 4.0 | Yes |
Application | symantec | antivirus_scan_engine | 4.3 | Yes |
Operating System | redhat | linux | - | No |