SonicWALL Global VPN Client Remote Format String Vulnerability
BID:26689
Info
SonicWALL Global VPN Client Remote Format String Vulnerability
| Bugtraq ID: | 26689 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6273 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2007 12:00AM |
| Updated: | Dec 13 2007 08:22PM |
| Credit: | SEC Consult reported this issue. |
| Vulnerable: |
SonicWALL Global VPN Client 4.0 .782 |
| Not Vulnerable: |
SonicWALL Global VPN Client 4.0 .830 |
Discussion
SonicWALL Global VPN Client Remote Format String Vulnerability
SonicWALL Global VPN Client is prone to a remote format-string vulnerability because it fails to properly sanitize user-supplied input before passing it as the format specifier to a formatted-printing function.
Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the application. Failed attempts may cause denial-of-service conditions.
Versions prior to SonicWALL Global VPN Client 4.0.0.830 are affected.
SonicWALL Global VPN Client is prone to a remote format-string vulnerability because it fails to properly sanitize user-supplied input before passing it as the format specifier to a formatted-printing function.
Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of the application. Failed attempts may cause denial-of-service conditions.
Versions prior to SonicWALL Global VPN Client 4.0.0.830 are affected.
Exploit / POC
SonicWALL Global VPN Client Remote Format String Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
The following proof of concept was supplied:
<Connection name=> AAAAAAAAAA%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%
x.%x
<HostName> BBBBBBBBBB%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%
x.%x.%x.%x.%x.%x.%x
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
The following proof of concept was supplied:
<Connection name=> AAAAAAAAAA%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%
x.%x
<HostName> BBBBBBBBBB%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%x.%
x.%x.%x.%x.%x.%x.%x
Solution / Fix
SonicWALL Global VPN Client Remote Format String Vulnerability
Solution:
The vendor released SonicWALL Global VPN Client 4.0.0.830 to address this issue. Please contact the vendor for more information.
Solution:
The vendor released SonicWALL Global VPN Client 4.0.0.830 to address this issue. Please contact the vendor for more information.
References
SonicWALL Global VPN Client Remote Format String Vulnerability
References:
References:
- SEC Consult Security Advisory < 20071204-0 > (SEC Consult)
- SonicWALL Global VPN Client Homepage (SonicWALL)