First published: Tue Feb 17 2004(Updated: )
McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trellix ePolicy Orchestrator | =3.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0095 is considered a high severity vulnerability due to its potential to cause denial of service and execute arbitrary code.
To fix CVE-2004-0095, users should update to the latest version of McAfee ePolicy Orchestrator that addresses this vulnerability.
CVE-2004-0095 can be exploited to cause memory consumption leading to a denial of service, and may allow remote code execution.
CVE-2004-0095 specifically affects McAfee ePolicy Orchestrator version 3.6.0.
Administrators should review their systems for the presence of ePolicy Orchestrator version 3.6.0 and implement necessary updates or mitigations.