>> McAfee ePolicy Orchestrator "logDetail()" Format String Vulnerability
Title : McAfee ePolicy Orchestrator "logDetail()" Format String Vulnerability VUPEN ID : VUPEN/ADV-2008-0866 CVE ID : CVE-2008-1357
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-03-13
Technical Description
A vulnerability has been identified in McAfee ePolicy Orchestrator, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a format string error in the "logDetail()" [applib.dll] and "_naimcomn_Log()" [nailog2.dll] function when logging user-supplied requests sent to port 8082/UDP while debug level is set to 8, which could be exploited by remote unauthenticated attackers to crash an affected application or execute arbitrary code via a specially crafted request containing a malformed "sender" field.