Thread-topic: [SA25173] McAfee SecurityCenter Subscription Manager ActiveX Control Buffer Overflow
>
> TITLE:
> McAfee SecurityCenter Subscription Manager ActiveX Control Buffer
> Overflow
>
> SECUNIA ADVISORY ID:
> SA25173
>
> VERIFY ADVISORY:
>
>
> CRITICAL:
> Highly critical
>
> IMPACT:
> System access
>
> WHERE:
> From remote
>
> SOFTWARE:
> McAfee Wireless Home Network Security 2006
>
> McAfee VirusScan Professional 8.x
>
> McAfee VirusScan Plus 2007
>
> McAfee VirusScan Enterprise 8.x
>
> McAfee VirusScan 9.x/2005
>
> McAfee VirusScan 8.x/2004
>
> McAfee VirusScan 10.x/2006
>
> McAfee Total Protection 2007
>
> McAfee SpamKiller 7.x
>
> McAfee SpamKiller 6.x
>
> McAfee SpamKiller 5.x
>
> McAfee SecurityCenter 7.x
>
> McAfee SecurityCenter 6.x
>
> McAfee QuickClean 6.x
>
> McAfee QuickClean 5.x
>
> McAfee QuickClean 4.x
>
> McAfee Privacy Service 6.x
>
> McAfee Personal Firewall Plus 7.x/2006
>
> McAfee PC Protection Plus 2007
>
> McAfee Internet Security Suite 2007
>
> McAfee Internet Security Suite 2006
>
> McAfee Internet Security Suite 2005
>
> McAfee AntiSpyware 6.x
>
> McAfee SecurityCenter 4.x
>
>
> DESCRIPTION:
> A vulnerability has been reported in various McAfee products, which
> can be exploited by malicious people to compromise a user's system.
>
> The vulnerability is caused due to an error within the SecurityCenter
> Subscription Manager ActiveX control (McSubMgr.dll) when handling the
> "IsOldAppInstalled()" method. This can be exploited to cause a buffer
> overflow via a specially crafted argument passed to the said method.
>
> Successful exploitation allows execution of arbitrary code when a
> user visits a malicious website.
>
> The vulnerability affects versions prior to 7.2.147 and 6.0.25.
>
> SOLUTION:
> The fix has reportedly been available via automatic updates since
> March 22, 2007.
>
> Update to Security Center version 7.2.147 and 6.0.25, or higher.
>
>
> Set the kill-bit for the affected ActiveX control.
>
> PROVIDED AND/OR DISCOVERED BY:
> Discovered by Peter Vreugdenhil and reported via iDefense Labs.
>
> ORIGINAL ADVISORY:
> McAfee:
>
>
> iDefense Labs:
> .
> php?id=528
>