McAfee ePolicy Orchestrator Common Management Agent Buffer Overflows Let Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1018363
|
|
SecurityTracker URL: http://securitytracker.com/id?1018363
|
|
CVE Reference: CVE-2006-5271
, CVE-2006-5272
, CVE-2006-5273
, CVE-2006-5274
(Links to External Site)
|
Date: Jul 11 2007
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Internet Security Systems (X-Force)
|
Description: Several vulnerabilities were reported in ePolicy Orchestrator. A remote user can execute arbitrary code on the target system.
A remote user can send specially crafted data to trigger a memory corruption error and execute arbitrary code on the target system.
The code will run with the privileges of the target service.
An integer underflow, stack overflow, heap overflow, and integer
underflow can be triggered in the Common Management Agent.
Neel Mehta of IBM ISS X-Force discovered these vulnerabilities.
The
original advisory is available at:
http://www.iss.net/threats/269.html
|
Impact: A remote user can execute arbitrary code on the target system.
|
Solution: The vendor has issued a fix (Common Management Agent 3.6.0 Patch 1 (CMA3.6.0.546)).
The McAfee advisories are available at:
https://knowledge.mcafee.com/SupportSite/
search.do?cmd=displayKC&docType=kc&sliceId=SAL_Public&externalId=613364
https://knowledge.mcafee.com/SupportSite/search.do?cmd=displayKC&docType=kc&sliceId=SAL_Public&ex
ternalId=613365
https://knowledge.mcafee.com/SupportSite/search.do?cmd=displayKC&docType=kc&sliceId=SAL_Public&externalId=613366
https://knowledge.mcafee.com/SupportSit
e/search.do?cmd=displayKC&docType=kc&sliceId=SAL_Public&externalId=613367
|
Vendor URL: www.mcafee.com/ (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Windows (2000), Windows (2003), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 11 Jul 2007 11:02:12 -0400
Subject: McAfee ePolicy Orchestrator Agent Remote Code Execution
|
http://www.iss.net/threats/269.html
CVE-2006-5271
CVE-2006-5272
CVE-2006-5273
CVE-2006-5274
|
|