René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

153 lines
5.3 KiB
JSON

{
"id": "CVE-2008-1357",
"sourceIdentifier": "cve@mitre.org",
"published": "2008-03-17T17:44:00.000",
"lastModified": "2018-10-11T20:31:59.903",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in a sender field in an AgentWakeup request to UDP port 8082. NOTE: this issue only exists when the debug level is 8."
},
{
"lang": "es",
"value": "Vulnerabilidad en el formato de cadena en la funci\u00f3n logDetail de applib.dlld en McAfee Common Management Agent (CMA) 3.6.0.574 (Parche 3) y anteriores, como se utiliza en ePolicy Orchestrator 4.0.0 build 1015, permite a atacantes remotos provocar una denegaci\u00f3n de servicio (ca\u00edda) o ejecutar c\u00f3digo de su elecci\u00f3n a trav\u00e9s de formatos de especificadores de formatos de cadena en un fichero de env\u00edo en una solicitud AgentWakeup en el puerto 8082. NOTA: esta vulnerabilidad s\u00f3lo sucede cuando se est\u00e1 en un nivel 8 de depuraci\u00f3n."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:H/Au:N/C:N/I:N/A:C",
"accessVector": "NETWORK",
"accessComplexity": "HIGH",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "COMPLETE",
"baseScore": 5.4
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 4.9,
"impactScore": 6.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-134"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mcafee:agent:4.0:*:*:*:*:*:*:*",
"matchCriteriaId": "43953695-9C35-4CC3-9591-D03866731F47"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mcafee:cma:3.0.6.453:*:*:*:*:*:*:*",
"matchCriteriaId": "9B7D230B-845A-4E83-B86C-000CDBAC937F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mcafee:cma:3.5.5.438:*:*:*:*:*:*:*",
"matchCriteriaId": "4A0590CC-B03B-472B-A5FF-F6A316DBE2DC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mcafee:cma:3.6.438:*:*:*:*:*:*:*",
"matchCriteriaId": "0BD368FB-2683-4321-9491-CB757511AD49"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mcafee:cma:3.6.453:*:*:*:*:*:*:*",
"matchCriteriaId": "F64F9F3F-F835-4769-9A5B-A05ED2AE7850"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mcafee:cma:3.6.546:*:*:*:*:*:*:*",
"matchCriteriaId": "3C0AE0A0-E56A-4B93-B45B-037C09EA69C3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mcafee:cma:3.6.574:*:*:*:*:*:*:*",
"matchCriteriaId": "CFF00F5B-4272-49CC-A9CE-4CCD20F5DB3E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mcafee:epolicy_orchestrator:4.0:*:*:*:*:*:*:*",
"matchCriteriaId": "485DB16F-730A-44B2-A255-2583AB27DB9C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mcafee:mcafee_framework:3.6.569:*:*:*:*:*:*:*",
"matchCriteriaId": "6330056D-1DAF-4821-90E5-1E9E52594A25"
}
]
}
]
}
],
"references": [
{
"url": "http://aluigi.altervista.org/adv/meccaffi-adv.txt",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://securityreason.com/securityalert/3748",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/489476/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/28228",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.securitytracker.com/id?1019609",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0866/references",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41178",
"source": "cve@mitre.org"
},
{
"url": "https://knowledge.mcafee.com/article/234/615103_f.sal_public.html",
"source": "cve@mitre.org"
}
]
}