First published: Tue Oct 03 2006(Updated: )
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee ePolicy Orchestrator | =3.0 | |
McAfee ProtectionPilot | =1.1.1 | |
McAfee ePolicy Orchestrator | =3.0-sp2a | |
McAfee ePolicy Orchestrator | =3.5.0 | |
=3.0 | ||
=3.0-sp2a | ||
=3.5.0 | ||
=1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5156 is considered critical due to its potential to allow remote code execution.
To fix CVE-2006-5156, upgrade to ePolicy Orchestrator version 3.5.0.720 or later and ProtectionPilot version 1.1.1.126 or later.
CVE-2006-5156 affects McAfee ePolicy Orchestrator versions prior to 3.5.0.720 and ProtectionPilot versions prior to 1.1.1.126.
CVE-2006-5156 allows attackers to execute arbitrary code via a specially crafted request.
CVE-2006-5156 was disclosed in 2006.