CVE-2003-0616

Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:epolicy_orchestrator:2.0:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:epolicy_orchestrator:2.5:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:epolicy_orchestrator:2.5:sp1:*:*:*:*:*:*
cpe:2.3:a:mcafee:epolicy_orchestrator:2.5.1:*:*:*:*:*:*:*

History

20 Nov 2024, 23:45

Type Values Removed Values Added
References () http://www.atstake.com/research/advisories/2003/a073103-1.txt - () http://www.atstake.com/research/advisories/2003/a073103-1.txt -
References () http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp - () http://www.nai.com/us/promos/mcafee/epo_vulnerabilities.asp -

Information

Published : 2003-08-27 04:00

Updated : 2024-11-20 23:45


NVD link : CVE-2003-0616

Mitre link : CVE-2003-0616

CVE.ORG link : CVE-2003-0616


JSON object : View

Products Affected

mcafee

  • epolicy_orchestrator