MEDIUM
Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands via long string parameters, which are later used in vsprintf
Published Aug 1, 2006
6.8
MEDIUMCVSS 2.0
EPSS 34.36%
Description
Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands via long string parameters, which are later used in vsprintf.
Affected products
No data.
OR
- 2005
- 2006
- 2004
- 2005
- 2006
- 2004
- 2005
- 2006
- 2004
- 2005
- 2006
- 2004
- 2005
- 2006
- 4.3
- 6.0
- 6.0.22
- 6.0.23
- 5.0
- 6.0
- 7.0
- 2004
- 2005
- 2006
- 2006
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://secunia.com/advisories/21264 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://securitytracker.com/id?1016614 vdb-entryx_refsource_SECTRACK
- http://ts.mcafeehelp.com/faq3.asp?docid=407052 x_refsource_CONFIRM
- http://www.eeye.com/html/research/advisories/AD2006807.html x_refsource_MISC
- http://www.eeye.com/html/research/upcoming/20060719.html x_refsource_MISC
- http://www.kb.cert.org/vuls/id/481212 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.osvdb.org/27698 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/442495/100/100/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/19265 vdb-entryx_refsource_BIDPatch
- http://www.vupen.com/english/advisories/2006/3096 vdb-entryx_refsource_VUPENVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-3954 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/21264 | third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory | |
| http://securitytracker.com/id?1016614 | vdb-entryx_refsource_SECTRACK | |
| http://ts.mcafeehelp.com/faq3.asp?docid=407052 | x_refsource_CONFIRM | |
| http://www.eeye.com/html/research/advisories/AD2006807.html | x_refsource_MISC | |
| http://www.eeye.com/html/research/upcoming/20060719.html | x_refsource_MISC | |
| http://www.kb.cert.org/vuls/id/481212 | third-party-advisoryx_refsource_CERT-VNUS Government Resource | |
| http://www.osvdb.org/27698 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/archive/1/442495/100/100/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/19265 | vdb-entryx_refsource_BIDPatch | |
| http://www.vupen.com/english/advisories/2006/3096 | vdb-entryx_refsource_VUPENVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-3954 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 1, 2006
Updated Aug 7, 2024
Reserved Aug 1, 2006
Link CVE-2006-3961
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-3954 Assigner mitre
Published Aug 1, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-3954