Vulnerabilities > CVE-2006-5272 - Unspecified vulnerability in Mcafee products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN mcafee
nessus
Summary
Stack-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and earlier allows remote attackers to execute arbitrary code via a crafted ping packet.
Vulnerable Configurations
Nessus
NASL family | CGI abuses |
NASL id | MCAFEE_CMA_3_6_0_546.NASL |
description | The McAfee Common Management Agent (CMA) running on the remote host is prior to version 3.6.0 Patch 1 (3.6.0.546). It is, therefore, affected by multiple vulnerabilities : - An integer underflow condition exists that allows an unauthenticated, remote attacker to execute arbitrary code via a specially crafted UDP packet. (CVE-2006-5271) - A stack-based buffer overflow condition exists due to improper checking of boundary limits when receiving ping packets. An unauthenticated, remote attacker can exploit this, via a specially crafted packet, to cause a denial of service condition or the execution of arbitrary code. (CVE-2006-5272) - A heap buffer overflow condition exists due to improper checking of bounds when receiving certain packets. An unauthenticated, remote attacker can exploit this, via a specially crafted packet, to cause a denial of service condition or the execution of arbitrary code. (CVE-2006-5273) - An integer overflow condition exists in the CMA Framework service that allows an unauthenticated, remote attacker to cause a denial of service condition or the execution of arbitrary code. (CVE-2006-5274) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25702 |
published | 2007-07-10 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25702 |
title | McAfee Common Management Agent < 3.6.0.546 Multiple Vulnerabilities |
code |
|
References
- http://secunia.com/advisories/26029
- http://secunia.com/advisories/26029
- http://www.iss.net/threats/269.html
- http://www.iss.net/threats/269.html
- http://www.osvdb.org/36099
- http://www.osvdb.org/36099
- http://www.securityfocus.com/bid/24863
- http://www.securityfocus.com/bid/24863
- http://www.securitytracker.com/id?1018363
- http://www.securitytracker.com/id?1018363
- http://www.vupen.com/english/advisories/2007/2498
- http://www.vupen.com/english/advisories/2007/2498
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31163
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31163
- https://knowledge.mcafee.com/article/762/613365_f.SAL_Public.html
- https://knowledge.mcafee.com/article/762/613365_f.SAL_Public.html