CVE-2006-5272: Buffer Overflow
Stack-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and earlier allows remote attackers to execute arbitrary code via a crafted ping packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5272?
CVE-2006-5272 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2006-5272?
To address CVE-2006-5272, you should upgrade to the latest versions of McAfee ePolicy Orchestrator, ProtectionPilot, and the Common Management Agent.
Which versions are affected by CVE-2006-5272?
CVE-2006-5272 impacts McAfee ePolicy Orchestrator versions 3.5 to 3.6.1, ProtectionPilot versions 1.1.1 and 1.5, and Common Management Agent versions prior to 3.6.0.454.
What kinds of attacks can CVE-2006-5272 enable?
CVE-2006-5272 allows remote attackers to execute arbitrary code by sending specially crafted ping packets.
Is there a workaround for CVE-2006-5272?
While upgrading is the recommended solution for CVE-2006-5272, temporarily restricting network access to the affected applications may reduce exposure.