Secunia Logo
 
CVE Reference: CVE-2005-3657
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-3657

Description:
The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Security Center does not use the IObjectSafetySiteLock API to restrict access to required domains, which allows remote attackers to create or append to arbitrary files via the StartLog and AddLog methods in the MCINSTALL.McLog object.

CVE Status:
Candidate

References:

ST
  1015390

SREASON
  http://securityreason.com/securityalert/279

SAID
  Secunia Advisory: SA18169

IDEFENSE
  http://www.idefense.com/intelligence/vulnerabilities/display.php?id=358

BID
  15986


Return to the previous page.