Log'N'Rock: Critical hole in McAfee products still open after more than 180 days - Update - Log'N'Rock

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Critical hole in McAfee products still open after more than 180 days - Update

#1 User is offline   Peaches4U Icon

  • Rockin' News Angel
  • Icon
  • Group: Road Crew
  • Posts: 2,911
  • Joined: 14-September 09
  • Gender:Female
  • Location:Canada
  • Interests:computers; travel; keeping busy; fashion;

Posted 20 January 2012 - 06:51 AM



Quote

Critical hole in McAfee products still open after more than 180 days - Update

Zero Day Initiative (ZDI) has released information on a security problem in McAfee's Security-as-a-Service products (SaaS). The vulnerability broker says that it told McAfee about the hole in April 2011, and that it has now decided to publicly release the information because the vendor still hasn't provided a patch. The flaw is contained in the myCIOScn.dll program library. In this library, the MyCioScan.Scan.ShowReport() method insufficiently filters user input and executes embedded commands within the context of the browser. The flaw can be exploited when a user opens a specially crafted file or web page. ZDI rates the issue as very severe and has given it a CVSS score of 9 – maximum severity is 10.


http://www.h-online....te-1413775.html




0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users