CVE-2008-1357
McAfee Framework ePolicy 3.x - Orchestrator '_naimcomn_Log' Remote Format String
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in a sender field in an AgentWakeup request to UDP port 8082. NOTE: this issue only exists when the debug level is 8.
Vulnerabilidad en el formato de cadena en la función logDetail de applib.dlld en McAfee Common Management Agent (CMA) 3.6.0.574 (Parche 3) y anteriores, como se utiliza en ePolicy Orchestrator 4.0.0 build 1015, permite a atacantes remotos provocar una denegación de servicio (caída) o ejecutar código de su elección a través de formatos de especificadores de formatos de cadena en un fichero de envío en una solicitud AgentWakeup en el puerto 8082. NOTA: esta vulnerabilidad sólo sucede cuando se está en un nivel 8 de depuración.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-03-12 First Exploit
- 2008-03-17 CVE Reserved
- 2008-03-17 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-134: Use of Externally-Controlled Format String
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/3748 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/489476/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1019609 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/0866/references | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41178 | Vdb Entry | |
https://knowledge.mcafee.com/article/234/615103_f.sal_public.html | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/31399 | 2008-03-12 | |
http://aluigi.altervista.org/adv/meccaffi-adv.txt | 2024-08-07 | |
http://www.securityfocus.com/bid/28228 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/29337 | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mcafee Search vendor "Mcafee" | Agent Search vendor "Mcafee" for product "Agent" | 4.0 Search vendor "Mcafee" for product "Agent" and version "4.0" | - |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Cma Search vendor "Mcafee" for product "Cma" | 3.0.6.453 Search vendor "Mcafee" for product "Cma" and version "3.0.6.453" | - |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Cma Search vendor "Mcafee" for product "Cma" | 3.5.5.438 Search vendor "Mcafee" for product "Cma" and version "3.5.5.438" | - |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Cma Search vendor "Mcafee" for product "Cma" | 3.6.438 Search vendor "Mcafee" for product "Cma" and version "3.6.438" | - |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Cma Search vendor "Mcafee" for product "Cma" | 3.6.453 Search vendor "Mcafee" for product "Cma" and version "3.6.453" | - |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Cma Search vendor "Mcafee" for product "Cma" | 3.6.546 Search vendor "Mcafee" for product "Cma" and version "3.6.546" | - |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Cma Search vendor "Mcafee" for product "Cma" | 3.6.574 Search vendor "Mcafee" for product "Cma" and version "3.6.574" | - |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Epolicy Orchestrator Search vendor "Mcafee" for product "Epolicy Orchestrator" | 4.0 Search vendor "Mcafee" for product "Epolicy Orchestrator" and version "4.0" | - |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Mcafee Framework Search vendor "Mcafee" for product "Mcafee Framework" | 3.6.569 Search vendor "Mcafee" for product "Mcafee Framework" and version "3.6.569" | - |
Affected
|