Overview
McAfee Virex automatic updates may not properly authenticate the source of updates. This may allow a remote attacker to execute arbitrary commands on a vulnerable system.
Description
McAfee Virex is anti-virus software for the Mac OS X platform. McAfee Virex 7 for Mac OS X connects to a remote FTP server to retrieve updates. However, Virex fails to properly authenticate the server or the contents of the retrieved updates. This may allow a remote attacker to spoof the update server and its contents, allowing that attacker to download and execute arbitrary commands on a Virex client system. |
Impact
A remote attacker can execute arbitrary commands. |
Solution
Apply a patch from McAfee Virex A patch to address this issue is available by visiting the McAfee SecurityCenter and clicking the update button. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Anthony Bellissimo, John Burgess, and Kevin Fu for reporting this vulnerability.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | None |
Severity Metric: | 0.11 |
Date Public: | 2006-07-31 |
Date First Published: | 2007-02-15 |
Date Last Updated: | 2007-02-16 12:32 UTC |
Document Revision: | 27 |