Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2002-1447

Overview

Vulnerability Score 7.2 7.2
CVE Id CVE-2002-1447
Last Modified 05 Sep 2008 04:30:37
Published 28 May 2002 12:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2002-1447

Summary

Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name in a connect argument.

Vulnerable Systems

Application

  • Cisco Vpn Client 3.5.1


References

MISC - http://sec.angrypacket.com/advisories/0002_AP.vpnclient.txt

BID - 5056

XF - ciscovpn-profile-name-bo(9376)

CISCO - 20020619 Buffer Overflow in UNIX VPN Client

BUGTRAQ - 20020619 [AP] Cisco vpnclient buffer overflow


Last Updated: 27 May 2016 10:37:20