RealSecure Server Sensor, RealSecure Network, BlackICE PC Protection, Proventia Server IPS for Microsoft Windows technology, BlackICE Server Protection, Proventia Network MFS, Proventia-G 1.1 and earlier, Proventia Desktop, Proventia Network IPS, Proventia Server IPS for Linux technology:
This signature detects an overflow from a HTTP POST request sent to a specific security management application which may result in arbitrary code execution.
High
RealSecure Server Sensor: XPU 24.56, RealSecure Network: XPU 24.56, BlackICE PC Protection: 3.6cqb, Proventia Server IPS for Microsoft Windows technology: 1.0.914.1960, BlackICE Server Protection: 3.6.cqb, Proventia Network MFS: XPU 1.95, Proventia-G 1.1 and earlier: XPU 24.56, Proventia Desktop: 1960, Proventia Network IPS: XPU 1.95, Proventia Server IPS for Linux technology: 1.95
McAfee ePolicy Orchestrator: 3.6.1, McAfee ProtectionPilot: 1.1.1, McAfee ProtectionPilot: 1.5, McAfee Common Management Agent: 3.6.0.453, McAfee ePolicy Orchestrator: 3.5.0, McAfee ePolicy Orchestrator: 3.6.0
Unauthorized Access Attempt
McAfee Common Management Agent (CMA), which is used in multiple McAfee products, is vulnerable to a stack-based buffer overflow, caused by improper bounds checking of pings. By sending a specially-crafted packet to an affected system, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the CMA node to crash.
Upgrade to the latest version of McAfee Common Management Agent (3.6.0 Patch 1 (CMA3.6.0.546) or later), as listed in McAfee Support Document ID: 613365. See References.
IBM Internet Security Systems Protection Advisory July 10, 2007
McAfee ePolicy Orchestrator Agent Remote Code Execution
http://www.iss.net/threats/269.html
McAfee Support Document ID: 613365
McAfee Security Bulletin - Stack based buffer overflow of Common Management Agent (CMA)
https://knowledge.mcafee.com/SupportSite/search.do?cmd=displayKC&docType=kc&sliceId=SAL_Public&externalId=613365
ISS X-Force
McAfee Common Management Agent (CMA) ping buffer overflow
http://www.iss.net/security_center/static/31163.php
CVE
CVE-2006-5272
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5272