RealSecure Desktop, Proventia Network IPS, Proventia Desktop, Proventia Network IDS, Proventia-G 1.1 and earlier, Proventia Network MFS, IBM Security Server Protection for Windows, BlackICE Server Protection, BlackICE PC Protection, RealSecure Network, RealSecure Server Sensor, Proventia Server IPS for Linux technology, Virtual Server Protection for Vmware:
This signature detects an overflow from a HTTP POST request sent to a specific security management application which may result in arbitrary code execution.
McAfee Common Management Agent (CMA), which is used in multiple McAfee products, is vulnerable to a stack-based buffer overflow, caused by improper bounds checking of pings. By sending a specially-crafted packet to an affected system, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the CMA node to crash.
High
RealSecure Desktop: eqb, Proventia Network IPS: XPU 1.95, Proventia Desktop: 1960, Proventia Network IDS: XPU 24.56, Proventia-G 1.1 and earlier: XPU 24.56, Proventia Network MFS: XPU 1.95, IBM Security Server Protection for Windows: 1.0.914.1960, IBM Security Server Protection for Windows: 2.1.14.2400, BlackICE Server Protection: 3.6.cqb, BlackICE PC Protection: 3.6cqb, RealSecure Network: XPU 24.56, RealSecure Server Sensor: XPU 24.56, Proventia Server IPS for Linux technology: 1.95, Virtual Server Protection for Vmware: 1.0
McAfee ePolicy Orchestrator: 3.6.1, McAfee ProtectionPilot: 1.1.1, McAfee ProtectionPilot: 1.5, McAfee Common Management Agent: 3.6.0.453, McAfee ePolicy Orchestrator: 3.5.0, McAfee ePolicy Orchestrator: 3.6.0
Unauthorized Access Attempt
McAfee Common Management Agent (CMA), which is used in multiple McAfee products, is vulnerable to a stack-based buffer overflow, caused by improper bounds checking of pings. By sending a specially-crafted packet to an affected system, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the CMA node to crash.
Upgrade to the latest version of McAfee Common Management Agent (3.6.0 Patch 1 (CMA3.6.0.546) or later), as listed in McAfee Support Document ID: 613365. See References.
IBM Internet Security Systems Protection Advisory July 10, 2007
McAfee ePolicy Orchestrator Agent Remote Code Execution
http://www.iss.net/threats/269.html
McAfee Support Document ID: 613365
McAfee Security Bulletin - Stack based buffer overflow of Common Management Agent (CMA)
https://knowledge.mcafee.com/SupportSite/search.do?cmd=displayKC&docType=kc&sliceId=SAL_Public&externalId=613365
ISS X-Force
McAfee Common Management Agent (CMA) ping buffer overflow
http://www.iss.net/security_center/static/31163.php
CVE
CVE-2006-5272
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5272