PT-2010-2175 · Thegreenbow · Thegreenbow Ipsec Vpn Client
Brett Gervasoni
·
Published
2010-01-26
·
Updated
2024-02-14
·
CVE-2010-0392
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TheGreenBow IPSec VPN Client versions 4.51.001 through 4.65.003
Description
A stack-based buffer overflow issue exists, allowing user-assisted remote attackers to execute arbitrary code via a long
OpenScriptAfterUp parameter in a policy (.tgb) file. This issue is related to the "phase 2" aspect of the software.Recommendations
For versions 4.51.001 through 4.65.003, avoid using long
OpenScriptAfterUp parameters in policy (.tgb) files to minimize the risk of exploitation. As a temporary workaround, consider restricting the use of the OpenScriptAfterUp parameter in the affected policy files until a patch is available.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thegreenbow Ipsec Vpn Client