Cisco Security Agent Buffer Overflow Protection Bypass Vulnerability
BID:11659
Info
Cisco Security Agent Buffer Overflow Protection Bypass Vulnerability
| Bugtraq ID: | 11659 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2004 12:00AM |
| Updated: | Nov 11 2004 12:00AM |
| Credit: | This vulnerability was disclosed by the vendor. |
| Vulnerable: |
Okena StormWatch 3.x Cisco Security Agent 4.0.3 Cisco Security Agent 4.0.2 Cisco Security Agent 4.0.1 Cisco Security Agent 4.0 Cisco Security Agent 3.x |
| Not Vulnerable: |
Cisco Security Agent 4.0.3 .728 |
Discussion
Cisco Security Agent Buffer Overflow Protection Bypass Vulnerability
It is reported that Cisco Security Agent is susceptible to a buffer overflow protection bypass vulnerability.
This vulnerability allows remote attackers to bypass the buffer overflow protections offered by Cisco Security Agent. This aids attackers in exploiting latent vulnerabilities in services protected by the affected package.
Versions prior to 4.0.3.728 are reported susceptible to this vulnerability.
It is reported that Cisco Security Agent is susceptible to a buffer overflow protection bypass vulnerability.
This vulnerability allows remote attackers to bypass the buffer overflow protections offered by Cisco Security Agent. This aids attackers in exploiting latent vulnerabilities in services protected by the affected package.
Versions prior to 4.0.3.728 are reported susceptible to this vulnerability.
Exploit / POC
Cisco Security Agent Buffer Overflow Protection Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Cisco Security Agent Buffer Overflow Protection Bypass Vulnerability
Solution:
The vendor has released an advisory (cisco-sa-20041111-csa) to address this issue. Please see the referenced advisory for further information. Users of affected packages are urged to contact the vendor for information on obtaining fixes.
Solution:
The vendor has released an advisory (cisco-sa-20041111-csa) to address this issue. Please see the referenced advisory for further information. Users of affected packages are urged to contact the vendor for information on obtaining fixes.
References
Cisco Security Agent Buffer Overflow Protection Bypass Vulnerability
References:
References: