PT-2010-2175 · Thegreenbow · Thegreenbow Ipsec Vpn Client
Brett Gervasoni
·
Publicado
2010-01-26
·
Atualizado
2024-02-14
·
CVE-2010-0392
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TheGreenBow IPSec VPN Client versions 4.51.001 through 4.65.003
Description
A stack-based buffer overflow issue exists, allowing user-assisted remote attackers to execute arbitrary code via a long
OpenScriptAfterUp parameter in a policy (.tgb) file. This issue is related to the "phase 2" aspect of the software.Recommendations
For versions 4.51.001 through 4.65.003, avoid using long
OpenScriptAfterUp parameters in policy (.tgb) files to minimize the risk of exploitation. As a temporary workaround, consider restricting the use of the OpenScriptAfterUp parameter in the affected policy files until a patch is available.Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Thegreenbow Ipsec Vpn Client