Vulnerability Note VU#842452
McAfee HTTP Server vulnerable to buffer overflow
OverviewA stack-based buffer overflow exists in the McAfee HTTP server that may allow a remote, unauthenticated attacker to execute arbitrary code.
I. DescriptionThe McAfee HTTP server (NAISERV.exe) is used in McAfee products, such as McAfee ePolicy Orchestrator and Protection Pilot. The McAfee HTTP Server is vulnerable to a stack-based buffer overflow that can be triggered by sending the server a malformed HTTP packet.
More information is available in McAfee Security Bulletin 8611438.
Note that exploit code for this vulnerability is publicly available.
II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary code.
III. SolutionApply a patch
McAfee addresses this vulnerability with the patches listed in McAfee Security Bulletin 8611438.
Limit Access to the McAfee HTTP Server
You may wish to block access to the vulnerable software from outside your network perimeter, specifically by blocking access to the ports used by the McAfee HTTP Server. This will limit your exposure to attacks. However, blocking at the network perimeter would still allow attackers within the perimeter of your network to exploit the vulnerability. The use of host-based firewalls in addition to network-based firewalls can help restrict access to specific hosts within the network. It is important to understand your network's configuration and service requirements before deciding what changes are appropriate.
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
| McAfee | Vulnerable | 4-Oct-2006 |
References
http://www.remote-exploit.org/advisories/mcafee-epo.pdf
http://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=8611438&sliceId=SAL_Public&command=show&forward=nonthreadedKC&kcId=8611438
Credit
This issue was reported by muts.
This document was written by Jeff Gennari.
Other Information
| Date Public: | 2006-10-02 |
| Date First Published: | 2006-10-05 |
| Date Last Updated: | 2006-10-05 |
| CERT Advisory: | |
| CVE-ID(s): | |
| NVD-ID(s): | |
| US-CERT Technical Alerts: | |
| Metric: | 18.56 |
| Document Revision: | 14 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|