CVE-2006-0559: Critical severity McAfee Webshield Smtp vulnerability
Published Apr 4, 2006
·Updated
Format string vulnerability in the SMTP server for McAfee WebShield 4.5 MR2 and earlier allows remote attackers to execute arbitrary code via format strings in the domain name portion of a destination address, which are not properly handled when a bounce message is constructed.
Affected Software
1 affected component
McAfee Webshield Smtp<=4.5
Remediation
Patch Available
Patch Available
Event History
Apr 4, 2006
CVE Published
02:04 PM
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0559?
CVE-2006-0559 is classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2006-0559?
To fix CVE-2006-0559, upgrade McAfee WebShield to version 4.5 MR2 or later.
3
What software is affected by CVE-2006-0559?
CVE-2006-0559 affects McAfee WebShield SMTP versions up to 4.5 MR2.
4
What type of attack does CVE-2006-0559 enable?
CVE-2006-0559 enables remote attackers to execute arbitrary code through a format string vulnerability.
5
What components of McAfee WebShield are impacted by CVE-2006-0559?
The SMTP server component of McAfee WebShield is impacted by CVE-2006-0559.