McAfee E-Business Server Auth Packet Handling Buffer Overflow
1 Nov. 2007
Summary
"http://www.mcafee.com/us/enterprise/products/encryption/ebusiness_server.html secures batch processes and protects sensitive company data and network traffic with 128-bit encryption and authentication, everywhere it is accessed, transferred, and stored". Secunia Research has discovered a vulnerability in McAfee E-Business Server, which can be exploited by malicious people to compromise a vulnerable system.
Vulnerable Systems:
* McAfee E-Business Server for Linux version 8.1.1
Immune Systems:
* E-Business Server version 8.5.3 for Solaris
* E-Business Server version 8.1.2 for Linux, HP-UX, AIX
The vulnerability is caused due to an integer overflow within the e-Business administration utility service when parsing authentication packets. This can be exploited to cause a heap-based buffer overflow via a specially crafted authentication packet with an overly large length value.
Successful exploitation allows execution of arbitrary code.
Solution:
Install E-Business Server 8.5.3 for Solaris, or install E-Business Server 8.1.2 for Linux, HP-UX, AIX.