CVE-2007-3024

Publication date 7 June 2007

Last updated 24 July 2024


Ubuntu priority

libclamav/others.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 uses insecure permissions for temporary files that are created by the cli_gentempstream function in clamd/clamdscan, which might allow local users to read sensitive files.

Status

Package Ubuntu Release Status
clamav 8.04 LTS hardy
Fixed 0.90.3-1
7.10 gutsy
Fixed 0.90.3-1
7.04 feisty
Fixed 0.90.2-0ubuntu1.3
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper
Fixed 0.92.1~dfsg2-1.1~dapper2