McAfee Antivirus Library is reported prone to a buffer overflow vulnerability. The issue is reported to exist in the LHA archive parser. The affected library does not perform sufficient bounds checking on LHA type two header file name fields before copying the data into a finite process buffer.
Vulnerable Systems:
* McAfee WebShield SMTP 4.5 and prior
Although unclear, it is reported that the LHA archive must be especially malformed and conform to an alternate non-archive file format in order to trigger the vulnerability.
A remote attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges on a computer that is running the affected software.
Vendor Status:
McAfee as issued an update for this vulnerablity.