SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#324929

McAfee VirusScan Enterprise heap buffer overflow vulnerability

Overview

The McAfee VirusScan progream contains a buffer overflow vulnerability. If exploited, this vulnerability may allow an attacker to arbitrary execute code.

I. Description

McAfee VirusScan Enterprise includes an anti-virus, firewall, and host-based intrusion protection system.

The on-demand virus scanner component of McAfee VirusScan Enterprise contains a heap buffer overflow vulnerability. This vulnerability occurs because the scanner fails to properly process files with long file names that contain multi-byte characters.

Note that per McAfee Security Bulletin 612750:

    In order for this attack to work, the target computer must have East Asia language files installed, and the default Unicode codepage must be set to a language which contains multi-byte characters--such as Chinese.

II. Impact

A remote, unauthenticated attacker may be able to execute arbitrary code with SYSTEM privileges or create a denial-of-service condition.

III. Solution

Update

McAfee has released VirusScan Enterprise 8.0i patch 12 to address this issue. See McAfee Security Bulletin 612750 for instructions on how to install this update directly or through McAfee's ePolicy Orchestrator.

Systems Affected

VendorStatusDate NotifiedDate Updated
McAfeeVulnerable21-Apr-2007

References


https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=612750&command=show&forward=nonthreadedKC
http://www.mcafee.com/us/enterprise/products/anti_virus/file_servers_desktops/virusscan_enterprise_80i.html
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=515
http://secunia.com/advisories/24914/

Credit

Thanks it iDefense labs and McAfee for information that was used in this report.

This document was written by Ryan Giobbi.

Other Information

Date Public:2007-04-17
Date First Published:2007-04-21
Date Last Updated:2007-04-21
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Metric:8.16
Document Revision:8

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader