CVE-2003-0149: Buffer Overflow
Published Aug 1, 2003
·Updated
Heap-based buffer overflow in ePO agent for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request containing long parameters.
Affected Software
4 affected components
McAfee ePolicy Orchestrator=2.5.1
McAfee ePolicy Orchestrator=2.5
McAfee ePolicy Orchestrator=2.5-sp1
McAfee ePolicy Orchestrator=2.0
Remediation
Patch Available
Event History
Aug 1, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Aug 27, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0149?
CVE-2003-0149 is considered critical due to the potential for remote code execution.
2
How do I fix CVE-2003-0149?
To fix CVE-2003-0149, upgrade to an unaffected version of McAfee ePolicy Orchestrator.
3
What are the affected versions listed under CVE-2003-0149?
The affected versions under CVE-2003-0149 include ePolicy Orchestrator 2.0, 2.5, 2.5-sp1, and 2.5.1.
4
Can CVE-2003-0149 be exploited remotely?
Yes, CVE-2003-0149 can be exploited remotely through specially crafted POST requests.
5
What type of vulnerability is CVE-2003-0149?
CVE-2003-0149 is a heap-based buffer overflow vulnerability.