McAfee ePolicy Orchestrator HTTP GET Request Format String Vulnerability
BID:7111
Info
McAfee ePolicy Orchestrator HTTP GET Request Format String Vulnerability
| Bugtraq ID: | 7111 |
| Class: | Design Error |
| CVE: |
CVE-2002-0690 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2003 12:00AM |
| Updated: | Jul 11 2009 09:06PM |
| Credit: | The discovery of this vulnerability has been credited to @stake. |
| Vulnerable: |
McAfee ePolicy Orchestrator 2.5.1 |
| Not Vulnerable: | |
Discussion
McAfee ePolicy Orchestrator HTTP GET Request Format String Vulnerability
A format string vulnerability has been discovered in the McAfee ePolicy Orchestrator Agent. The issue occurs when processing HTTP GET requests that contain format specifiers. The successful exploitation of this vulnerability may allow an attacker to execute arbitrary commands with SYSTEM privileges.
A format string vulnerability has been discovered in the McAfee ePolicy Orchestrator Agent. The issue occurs when processing HTTP GET requests that contain format specifiers. The successful exploitation of this vulnerability may allow an attacker to execute arbitrary commands with SYSTEM privileges.
Solution / Fix
McAfee ePolicy Orchestrator HTTP GET Request Format String Vulnerability
Solution:
It has been reported that a patch for this issue has been developed. Information on how to obtain this fix is available in the attached @stake advisory.
Solution:
It has been reported that a patch for this issue has been developed. Information on how to obtain this fix is available in the attached @stake advisory.