CVE-2007-1498
Last modified
CVE-2007-1498 is a vulnerability of currently unknown severity. Multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy Orchestrator (ePO) before 3.6.1 Patch 1 and ProtectionPilot (PRP) before 1.5.0 HotFix allow remote attackers to execute arbitrary code via a long argument to the (1) ExportSiteList and (2) VerifyPackageCatalog functions, and (3) unspecified vectors involving a swprintf function call.. EPSS estimates a 7.73% chance of exploitation in the next 30 days.
Description
Multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy Orchestrator (ePO) before 3.6.1 Patch 1 and ProtectionPilot (PRP) before 1.5.0 HotFix allow remote attackers to execute arbitrary code via a long argument to the (1) ExportSiteList and (2) VerifyPackageCatalog functions, and (3) unspecified vectors involving a swprintf function call.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Mcafee | Epolicy Orchestrator | 3.5.0 | — |
| Mcafee | Epolicy Orchestrator | 3.6.0 | — |
| Mcafee | Epolicy Orchestrator | 3.6.1 | — |
| Mcafee | Protectionpilot | 1.1.1 | P3 |
| Mcafee | Protectionpilot | 1.5.0 | — |
References
- http://secunia.com/advisories/24466Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/714593US Government Resource
- http://secunia.com/advisories/24466Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/714593US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1498?
How severe is CVE-2007-1498?
How do I fix CVE-2007-1498?
Are you affected by CVE-2007-1498?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
