PT-2010-2175 · Thegreenbow · Thegreenbow Ipsec Vpn Client

·

CVE-2010-0392

·

Published

2010-01-26

·

Updated

2024-02-14

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TheGreenBow IPSec VPN Client versions 4.51.001 through 4.65.003
Description A stack-based buffer overflow issue exists, allowing user-assisted remote attackers to execute arbitrary code via a long OpenScriptAfterUp parameter in a policy (.tgb) file. This issue is related to the "phase 2" aspect of the software.
Recommendations For versions 4.51.001 through 4.65.003, avoid using long OpenScriptAfterUp parameters in policy (.tgb) files to minimize the risk of exploitation. As a temporary workaround, consider restricting the use of the OpenScriptAfterUp parameter in the affected policy files until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-0392

Affected Products

Thegreenbow Ipsec Vpn Client