McAfee ePolicy Orchestrator Agent POST Request Heap Overflow Vulnerability
BID:8316
Info
McAfee ePolicy Orchestrator Agent POST Request Heap Overflow Vulnerability
| Bugtraq ID: | 8316 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0149 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery is credited to Andreas Junestam <[email protected]>. |
| Vulnerable: |
McAfee ePolicy Orchestrator 2.5.1 McAfee ePolicy Orchestrator 2.5 SP1 McAfee ePolicy Orchestrator 2.5 McAfee ePolicy Orchestrator 2.0 |
| Not Vulnerable: | |
Discussion
McAfee ePolicy Orchestrator Agent POST Request Heap Overflow Vulnerability
McAfee ePolicy Orchestrator Agent has been reported prone to a heap overflow vulnerability when processing POST requests of excessive length.
The vulnerability presents itself, likely due to a lack of sufficient bounds checking performed on POST requests received by the agent. It has been reported that a remote attacker may lever this condition to supply and execute arbitrary instructions.
McAfee ePolicy Orchestrator Agent has been reported prone to a heap overflow vulnerability when processing POST requests of excessive length.
The vulnerability presents itself, likely due to a lack of sufficient bounds checking performed on POST requests received by the agent. It has been reported that a remote attacker may lever this condition to supply and execute arbitrary instructions.
Exploit / POC
McAfee ePolicy Orchestrator Agent POST Request Heap Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
McAfee ePolicy Orchestrator Agent POST Request Heap Overflow Vulnerability
Solution:
The vendor has released a fix to address this issue:
McAfee ePolicy Orchestrator 2.0
McAfee ePolicy Orchestrator 2.5 SP1
McAfee ePolicy Orchestrator 2.5
McAfee ePolicy Orchestrator 2.5.1
Solution:
The vendor has released a fix to address this issue:
McAfee ePolicy Orchestrator 2.0
-
Network Associates EPO2X2.Zip
McAfee ePolicy Orchestrator 2.X Patch 2
http://download.nai.com/products/patches/ePO/v2.x/
McAfee ePolicy Orchestrator 2.5 SP1
-
Network Associates EPO2X2.Zip
McAfee ePolicy Orchestrator 2.X Patch 2
http://download.nai.com/products/patches/ePO/v2.x/
McAfee ePolicy Orchestrator 2.5
-
Network Associates EPO2X2.Zip
McAfee ePolicy Orchestrator 2.X Patch 2
http://download.nai.com/products/patches/ePO/v2.x/
McAfee ePolicy Orchestrator 2.5.1
-
Network Associates EPO2X2.Zip
McAfee ePolicy Orchestrator 2.X Patch 2
http://download.nai.com/products/patches/ePO/v2.x/
References
McAfee ePolicy Orchestrator Agent POST Request Heap Overflow Vulnerability
References:
References:
- Network Associates Security Bulletin 07/31/03 (Network Associates Inc.)