Vulnerability CVE-2008-1357


Published: 2008-03-17   Modified: 2012-02-12

Description:
Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in a sender field in an AgentWakeup request to UDP port 8082. NOTE: this issue only exists when the debug level is 8.

See advisories in our WLB2 database:
Topic
Author
Date
High
Format string in McAfee Framework 3.6.0.569 (ePolicy Orchestrator 4.0)
Luigi Auriemma
17.03.2008

Type:

CWE-134

(Uncontrolled Format String)

Vendor: Mcafee
Product: Agent 
Version: 4.0;
Product: Epolicy orchestrator 
Version: 4.0;
Product: CMA 
Version:
3.6.574
3.6.546
3.6.453
3.6.438
3.5.5.438
3.0.6.453
Product: Mcafee framework 
Version: 3.6.569;

CVSS2 => (AV:N/AC:H/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.4/10
6.9/10
4.9/10
Exploit range
Attack complexity
Authentication
Remote
High
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete

 References:
http://aluigi.altervista.org/adv/meccaffi-adv.txt
http://securityreason.com/securityalert/3748
http://www.securityfocus.com/archive/1/489476/100/0/threaded
http://www.securityfocus.com/bid/28228
http://www.securitytracker.com/id?1019609
http://www.vupen.com/english/advisories/2008/0866/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/41178
https://knowledge.mcafee.com/article/234/615103_f.sal_public.html

Related CVE
CVE-2019-3621
Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows physical local user to bypass the Windows lock screen via DLPe processes being killed just prior to the screen being locked o...
CVE-2019-3622
Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to the DLPe lo...
CVE-2019-3595
Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code with their local machine privil...
CVE-2019-3591
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows unauthenticated remote user to trigger specially crafted JavaScript to...
CVE-2019-3592
Privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3, allows local administrator users to potentially disable some McAfee processes by manipulating the MA directory control and placing a carefully constructed file in the MA direct...
CVE-2019-3619
Information Disclosure vulnerability in the Agent Handler in McAfee ePolicy Orchestrator (ePO) 5.9.x and 5.10.0 prior to 5.10.0 update 4 allows remote unauthenticated attacker to view sensitive information in plain text via sniffing the traffic betwe...
CVE-2019-3632
Directory Traversal vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to gain elevated privileges via specially crafted input.
CVE-2019-3631
Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters.

Copyright 2019, cxsecurity.com

 

Back to Top