The Last HOPE
-->
         
         
Email us! Subscribe to Liquidmatrix!

McAfee ePolicy Orchestrator Buffer Overflows

There is a highly critical vulnerability in McAfee’s ePolicy Orchestrator. The description from Secunia follows:

Description:
cocoruder has reported some vulnerabilities in McAfee ePolicy Orchestrator and ProtectionPilot, which can be exploited by malicious people to compromise a user’s system.

The vulnerabilities are caused due to boundary errors within the SITEMANAGER.DLL ActiveX Control when processing arguments passed to the “ExportSiteList()” and “VerifyPackageCatalog()” methods. These can be exploited to cause stack-based buffer overflows via an overly long string passed as argument to the affected methods.

Successful exploitation allows execution of arbitrary code.

The vulnerabilities affect the following products:
* McAfee ePolicy Orchestrator 3.5.0 (Patch 5 and earlier)
* McAfee ePolicy Orchestrator 3.6.0 (Patch 5 earlier)
* McAfee ePolicy Orchestrator 3.6.1
* McAfee ProtectionPilot 1.1.1 (Patch 3 and earlier)
* McAfee ProtectionPilot 1.5.0

Solution:
Apply hotfix/patch.
https://mysupport.mcafee.com/eservice_enu/start.swe

Article Link

Tags: , ,

Tag It: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • Fark
  • YahooMyWeb
  • Furl
  • Spurl
  • Ma.gnolia
  • NewsVine
Related Articles:

  • Your July 19th Morning Coffee
  • Symantec Mail Security Buffer Overflows
  • McAfee VirusScan Exploit
  • Checkpoint Firewall 1 Exploits Discovered
  • AOL YGPPDownload ActiveX Control Buffer Overflows
  • Leave a Comment