b374k
v10
today : | at : | safemode : ON
> / home / facebook / twitter / exit /
name author perms com modified label

Vulnerabilities in McAfee enterprise system gives hacker root access Asylum rwxr-xr-x 0 4:41 PM

Filename Vulnerabilities in McAfee enterprise system gives hacker root access
Permission rw-r--r--
Author Asylum
Date and Time 4:41 PM
Label
Action
(pc-google images)
McAfee has issued patches for ten flaws in its enterprise version of VirusScan for Linux that allow attackers to remotely take over a system, after originally being notified of the security holes six months ago.

Security researcher Andrew Fasano from MIT Lincoln Laboratory said that a total of 10 security flaws allows the execution of code remotely as a root user.

“At a first glance, Intel's McAfee VirusScan Enterprise for Linux has all the best characteristics that vulnerability researchers love: it runs as root, it claims to make your machine more secure, it's not particularly popular, and it looks like it hasn't been updated in a long time,” he explained.

Four of the flaws are deemed critical. Attackers can exploit CVE-2016-8020, CVE-2016-8021, CVE-2016-8022, and CVE-2016-8023 to escalate their privileges to root and remotely force the target machine to run malicious script.

The six additional flaws involve a cross-site scripting vulnerability, file test and read bugs, HTTP response splitting, tokens forgery, and authenticated SQL injection.

All these vulnerabilities have already been confirmed in version 1.9.2 to 2.0.2, so all Linux systems are recommended to update to the latest release that McAfee shipped this month.


via E Hacking News - Latest Hacker News and IT Security News Vulnerabilities in McAfee enterprise system gives hacker root access http://ift.tt/2h7sUe9

0 comments:

Post a Comment

 

Jayalah Indonesiaku © 2010 Hacker News
VB (Vio b374k) Template design by p4r46hcyb3rn3t