CVE-2007-2957Improper Restriction of Operations within the Bounds of a Memory Buffer in E-business Server

CWE-1894 documents4 sources
Severity
9.3CRITICALNVD
EPSS
8.1%
top 7.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 31
Latest updateMay 1

Description

Integer overflow in McAfee E-Business Server before 8.5.3 for Solaris, and before 8.1.2 for Linux, HP-UX, and AIX, allows remote attackers to execute arbitrary code via a large length value in an authentication packet, which results in a heap-based buffer overflow.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m782-qx46-pj8h: Integer overflow in McAfee E-Business Server before 82022-05-01
CVEList
CVE-2007-2957: Integer overflow in McAfee E-Business Server before 82007-10-31

💬Community

1
Bugzilla
CVE-2008-2957 pidgin: unrestricted download of arbitrary files triggered via UPnP2008-07-02
CVE-2007-2957 — Mcafee E-business Server vulnerability | cvebase