RealSecure Server Sensor, RealSecure Network, BlackICE PC Protection, Proventia Server IPS for Microsoft Windows technology, BlackICE Server Protection, Proventia Network MFS, Proventia-G 1.1 and earlier, Proventia Desktop, Proventia Network IPS, Proventia Server IPS for Linux technology:
This signature detects a message to a specific security management application which contains a variable length string field with an invalid length specification. The application may receive this data through either TCP or UDP communications.
High
RealSecure Server Sensor: XPU 24.56, RealSecure Network: XPU 24.56, BlackICE PC Protection: 3.6cqb, Proventia Server IPS for Microsoft Windows technology: 1.0.914.1960, BlackICE Server Protection: 3.6.cqb, Proventia Network MFS: XPU 1.95, Proventia-G 1.1 and earlier: XPU 24.56, Proventia Desktop: 1960, Proventia Network IPS: XPU 1.95, Proventia Server IPS for Linux technology: 1.95
McAfee ePolicy Orchestrator: 3.6.0, McAfee ePolicy Orchestrator: 3.5.0, McAfee ProtectionPilot: 1.5, McAfee Common Management Agent: 3.5.5.438, McAfee ProtectionPilot: 1.1.1, McAfee ePolicy Orchestrator: 3.6.1
Unauthorized Access Attempt
McAfee Common Management Agent (CMA), which is used in multiple McAfee products, is vulnerable to an integer overflow. A remote attacker could exploit this vulnerability to execute arbitrary code on the affected system or cause a denial of service.
Upgrade to the latest version of McAfee Common Management Agent for version 3.5.5 (3.5.5 Patch 1 (CMA3.5.5.568) or later), as listed in McAfee Support Document ID: 613367. See References.
IBM Internet Security Systems Protection Advisory July 10, 2007
McAfee ePolicy Orchestrator Agent Remote Code Execution
http://www.iss.net/threats/269.html
McAfee Support Document ID: 613367
McAfee Security Bulletin - Crash of Framework service of McAfee Common Management Agent (CMA)
https://knowledge.mcafee.com/SupportSite/search.do?cmd=displayKC&docType=kc&sliceId=SAL_Public&externalId=613367
ISS X-Force
McAfee Common Management Agent (CMA) integer overflow
http://www.iss.net/security_center/static/31165.php
CVE
CVE-2006-5274
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5274