Vulnerability Description
Integer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 allows remote attackers to cause a denial of service (CMA Framework service crash) and possibly execute arbitrary code via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Common Management Agent | 3.6.0.438 |
| Mcafee | Epolicy Orchestrator | 3.5.0 |
| Mcafee | Protectionpilot | 1.1.1 |
References
- http://secunia.com/advisories/26029Vendor Advisory
- http://www.iss.net/threats/269.html
- http://www.osvdb.org/36101
- http://www.securityfocus.com/bid/24863
- http://www.securitytracker.com/id?1018363
- http://www.vupen.com/english/advisories/2007/2498
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31165
- https://knowledge.mcafee.com/article/764/613367_f.SAL_Public.htmlPatch
- http://secunia.com/advisories/26029Vendor Advisory
- http://www.iss.net/threats/269.html
- http://www.osvdb.org/36101
- http://www.securityfocus.com/bid/24863
- http://www.securitytracker.com/id?1018363
- http://www.vupen.com/english/advisories/2007/2498
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31165
FAQ
What is CVE-2006-5274?
CVE-2006-5274 is a vulnerability with a CVSS score of 7.6 (HIGH). Integer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 allows remote attackers to cause a denial of service (CMA ...
How severe is CVE-2006-5274?
CVE-2006-5274 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-5274?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Common Management Agent, Mcafee Epolicy Orchestrator, Mcafee Protectionpilot.