First published: Tue Aug 01 2006(Updated: )
Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands via long string parameters, which are later used in vsprintf.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Antispyware | =2005 | |
McAfee Antispyware | =2006 | |
McAfee Internet Security Suite | =2004 | |
McAfee Internet Security Suite | =2005 | |
McAfee Internet Security Suite | =2006 | |
McAfee Personal Firewall Plus | =2004 | |
McAfee Personal Firewall Plus | =2005 | |
McAfee Personal Firewall Plus | =2006 | |
McAfee Privacy Service | =2004 | |
McAfee Privacy Service | =2005 | |
McAfee Privacy Service | =2006 | |
McAfee QuickClean | =2004 | |
McAfee QuickClean | =2005 | |
McAfee QuickClean | =2006 | |
McAfee Security Center | =4.3 | |
McAfee Security Center | =6.0 | |
McAfee Security Center | =6.0.22 | |
McAfee Security Center | =6.0.23 | |
McAfee SpamKiller | =5.0 | |
McAfee SpamKiller | =6.0 | |
McAfee SpamKiller | =7.0 | |
McAfee VirusScan Plus | =2004 | |
McAfee VirusScan Plus | =2005 | |
McAfee VirusScan Plus | =2006 | |
McAfee Wireless Home Network Security | =2006 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3961 is classified as a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2006-3961, update to the latest version of McAfee products affected by this vulnerability.
CVE-2006-3961 affects multiple McAfee products including Security Center, VirusScan, SpamKiller, and Privacy Service.
Yes, CVE-2006-3961 can be exploited by remote user-assisted attackers.
CVE-2006-3961 is a buffer overflow vulnerability in the McSubMgr ActiveX control.