Secunia Security Advisory - RedXII1234 has discovered a security issue in AVG Anti-Virus, which potentially can be exploited by malicious, local users to gain escalated privileges.
edadf1f6b740ff839bca25ed3262d7843310e2ca990a06bcd468681fffd701e4
TITLE:
AVG Anti-Virus Updated Files Insecure File Permissions
SECUNIA ADVISORY ID:
SA19118
VERIFY ADVISORY:
http://secunia.com/advisories/19118/
CRITICAL:
Less critical
IMPACT:
Privilege escalation
WHERE:
Local system
SOFTWARE:
AVG Antivirus Professional
http://secunia.com/product/336/
AVG Antivirus 6.x
http://secunia.com/product/335/
AVG Anti-Virus Free Edition 7.x
http://secunia.com/product/6489/
DESCRIPTION:
RedXII1234 has discovered a security issue in AVG Anti-Virus, which
potentially can be exploited by malicious, local users to gain
escalated privileges.
The security issue is caused due to the File Update functionality
assigning insecure permissions to files that have been updated. This
can potentially be exploited by malicious users to delete or replace
the updated files.
The security issue has been confirmed in version 7.1.375 (Free
Edition). Other versions may also be affected
SOLUTION:
Restrict user access to affected systems.
PROVIDED AND/OR DISCOVERED BY:
RedXII1234
ORIGINAL ADVISORY:
http://www.dslreports.com/forum/remark,15601404
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------