CVE-2006-5156: Buffer Overflow
Published Oct 4, 2006
·Updated
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.
Affected Software
4 affected components
Mcafee ePolicy Orchestrator=3.0
Mcafee ProtectionPilot=1.1.1
Mcafee ePolicy Orchestrator=3.0-sp2a
Mcafee ePolicy Orchestrator=3.5.0
Remediation
Patch Available
Event History
Oct 4, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Oct 5, 2006
Data Sourced
via NVD·04:04 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-5156?
CVE-2006-5156 is considered critical due to its potential to allow remote code execution.
2
How do I fix CVE-2006-5156?
To fix CVE-2006-5156, upgrade to ePolicy Orchestrator version 3.5.0.720 or later and ProtectionPilot version 1.1.1.126 or later.
3
What products are affected by CVE-2006-5156?
CVE-2006-5156 affects McAfee ePolicy Orchestrator versions prior to 3.5.0.720 and ProtectionPilot versions prior to 1.1.1.126.
4
What kind of attack is possible with CVE-2006-5156?
CVE-2006-5156 allows attackers to execute arbitrary code via a specially crafted request.
5
When was CVE-2006-5156 disclosed?
CVE-2006-5156 was disclosed in 2006.