October 3, 2006 5:38 PM PDT

McAfee patches critical flaw in corporate products

McAfee has patched a "critical" flaw in its ePolicy Orchestrator and ProtectionPilot software that could enable an intruder to take over a vulnerable system. The problem affects ePolicy Orchestrator version 3.5.0 Patch 5 and earlier, and ProtectionPilot 1.1.1 Patch 2 and earlier, the security provider said in an advisory Monday.

The problem lies in the HTTP server component of the corporate security products, according to an advisory sent to subscribers to Symantec's Deepsight service. A remote attacker could send a malicious HTTP GET request containing code to overflow the buffer on a vulnerable machine and fully compromise it, Symantec said. It noted that an exploit for the hole is already in circulation.

See more CNET content tagged:
McAfee Inc., flaw, patch management, Symantec Corp., security

 

Join the conversation

Add your comment

The posting of advertisements, profanity, or personal attacks is prohibited. Click here to review our Terms of Use.

Inside CNET News

1-2 of 12

Scroll Left Scroll Right

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

Markets

Market news, charts, SEC filings, and more

Related quotes

McAfee (0.00%) 0.00 47.95
Dow Jones Industrials (0.57%) 72.81 12,874.04
S&P 500 (0.68%) 9.13 1,351.77
NASDAQ (0.95%) 27.51 2,931.39
CNET TECH (0.84%) 17.13 2,049.14
  Symbol Lookup