CVE-2008-1357
Summary
| CVE | CVE-2008-1357 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-03-17 17:44:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in a sender field in an AgentWakeup request to UDP port 8082. NOTE: this issue only exists when the debug level is 8. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:H/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Agent | 4.0 | All | All | All |
| Application | Mcafee | Cma | 3.0.6.453 | All | All | All |
| Application | Mcafee | Cma | 3.5.5.438 | All | All | All |
| Application | Mcafee | Cma | 3.6.438 | All | All | All |
| Application | Mcafee | Cma | 3.6.453 | All | All | All |
| Application | Mcafee | Cma | 3.6.546 | All | All | All |
| Application | Mcafee | Cma | 3.6.574 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 4.0 | All | All | All |
| Application | Mcafee | Mcafee Framework | 3.6.569 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| aluigi.altervista.org/adv/meccaffi-adv.txt | af854a3a-2127-422b-91ae-364da2661108 | aluigi.altervista.org | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| McAfee Framework ePolicy Orchestrator '_naimcomn_Log' Remote Format String Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| SecurityReason - Format string in McAfee Framework 3.6.0.569 (ePolicy Orchestrator 4.0) | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| SecurityTracker.com Archives - McAfee ePolicy Orchestrator Format String Bug Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| knowledge.mcafee.com/article/234/615103_f.sal_public.html | af854a3a-2127-422b-91ae-364da2661108 | knowledge.mcafee.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| McAfee ePolicy Orchestrator Framework Service Format String Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.