McAfee ePolicy Orchestrator Agent HTTP POST Buffer Mismanagement Vulnerability
10 Apr. 2012
Summary
The McAfee ePolicy Orchestrator agent has been reported to a buffer management vulnerability that may be exploited to crash the affected agent. Although unconfirmed, it has been reported that the issue may also allow a remote attacker to trigger a buffer overflow vulnerability.
Vulnerable Systems:
*McAfee ePolicy Orchestrator 3.0 and prior
The issue reportedly presents itself, because certain values in HTTP POST headers processed by the ePolicy Orchestrator are not sufficiently sanitized.
Vendor Status:
McAfee as issued an update for this vulnerablity.