McAfee Webshield SMTP Remote Format String Vulnerability
BID:16742
Info
McAfee Webshield SMTP Remote Format String Vulnerability
| Bugtraq ID: | 16742 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0559 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 03 2006 12:00AM |
| Updated: | Jun 27 2007 09:28PM |
| Credit: | Ollie Whitehouse <[email protected]> of Symantec Consulting Services discovered this vulnerability. |
| Vulnerable: |
McAfee WebShield SMTP 4.5 MR1a |
| Not Vulnerable: |
McAfee WebShield SMTP 4.5 MR2 |
Discussion
McAfee Webshield SMTP Remote Format String Vulnerability
McAfee WebShield SMTP is susceptible to a remote format-string vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before including it in a format-specifier argument to a formatted-printing function.
This issue allows remote attackers to execute arbitrary machine code in the context of the affected application.
McAfee WebShield SMTP is susceptible to a remote format-string vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before including it in a format-specifier argument to a formatted-printing function.
This issue allows remote attackers to execute arbitrary machine code in the context of the affected application.
Exploit / POC
McAfee Webshield SMTP Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
McAfee Webshield SMTP Remote Format String Vulnerability
Solution:
The vendor has released a patch (P0803), along with version 4.5 MR2 to address this issue. Users of affected packages should contact the vendor for information on obtaining fixes.
Solution:
The vendor has released a patch (P0803), along with version 4.5 MR2 to address this issue. Users of affected packages should contact the vendor for information on obtaining fixes.
References
McAfee Webshield SMTP Remote Format String Vulnerability
References:
References:
- McAfee WebShield SMTP Home Page (McAfee)
- SYMSA-2006-002: McAfee WebShield SMTP Format String Vulnerability (CS_Advisories Mailbox
)