SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

McAfee E-Business Server Remote Preauth Code Execution / DoS


Arrow  SecurityAlert : 3530
Arrow  CVE : CVE-2008-0127
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Available : Yes
Arrow  Credit : Leon Juranic
Arrow  Published : 10.01.2008

Arrow  Affected Software : McAfee E-Business Server 8.5.2



Arrow  Advisory Content :  


INFIGO IS Security Advisory #ADV-2008-01-06
http://www.infigo.hr/en/

Title: McAfee E-Business Server Remote Preauth Code Execution / DoS
Advisory ID: INFIGO-2008-01-06
Date: 2008-01-09
Advisory URL:
http://www.infigo.hr/en/in_focus/advisories/INFIGO-2008-01-06
Impact: Remote code execution
Risk Level: High
Vulnerability Type: Remote

==[ Overview

McAfee E-Business Server guards sensitive corporate data with
industry-standard
PGP 128-bit encryption and authentication. McAfee E-Business Server
supports
a
variety of platforms and security certificates.

==[ Vulnerability

During an audit of McAfee E-Business Server, we have discovered a
vulnerability
in the administration interface (TCP port 1718).
It is possible to crash McAfee E-Business Server during the authentication
process.
When a malformed (oversized) initial authentication packet is sent to
E-Business Server,
the server will crash, and will have to be manually restarted.

A malformed authentication packet is shown below:
"x01x3fx2fx05x25x2a" + "A" * 69953

McAfee further researched the vulnerability and confirmed that it allows
an
attacker
to also remotely execute code.

==[ Affected Version

The vulnerability has been identified in the latest available McAfee
E-Business Server 8.5.2, and it was successfully tested on Windows and
Linux
platforms.
Previous versions are believed to be vulnerable as well.

==[ Fix

The vendor has addressed this vulnerability with E-Business server patch
update
on January 8th, 2008.

Vendor advisory and update link:
https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=614472&
sliceId=SAL_Public&command=show&forward=nonthreadedKC&kcId=614472

==[ PoC Exploit

http://www.infigo.hr/files/mcafee2.pl

==[ Vendor status

11.28.2007 - Initial contact
11.29.2007 - Initial vendor response
11.30.2007 - Vendor response
12.03.2007 - Vendor status update
12.10.2007 - Vendor status update
12.17.2007 - Vendor status update
01.07.2008 - Vendor status update
01.09.2008 - Coordinated public disclosure

==[ Credits

Vulnerability discovered by Leon Juranic <leon.juranic (at) infigo (dot) hr
[email concealed]>.

==[ INFIGO IS Security Contact

INFIGO IS,

WWW : http://www.infigo.hr/en/
E-mail : infocus (at) infigo (dot) hr [email concealed]






Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.