vendor:
VPN Client
by:
angrypacket crew
7.2
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: VPN Client
Affected Version From: 3.5.2001
Affected Version To: 3.5.2001
Patch Exists: YES
Related CWE: N/A
CPE: a:cisco:vpn_client
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Solaris, Mac OS X
2002
Cisco VPN Client Buffer Overflow Vulnerability
A vulnerability has been reported in some versions of the Cisco VPN Client. If an oversized profile name is passed to the vpnclient binary, a buffer overflow condition may occur. As vpnclient runs suid root, exploitation of this vulnerability will grant a local attacker root access to the vulnerable system. This vulnerability affects the VPN Client version 3.5.1 for Linux, Solaris and Mac OS X. Windows clients are not believed to be vulnerable. Earlier versions of the VPN Client may share this vulnerability, although this has not been confirmed.
Mitigation:
Upgrade to the latest version of the Cisco VPN Client software.