OpenConnect 'webvpn' Cookie Debugging Output Information Disclosure Vulnerability
BID:44111
Info
OpenConnect 'webvpn' Cookie Debugging Output Information Disclosure Vulnerability
| Bugtraq ID: | 44111 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2010-3902 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2010 12:00AM |
| Updated: | Apr 13 2015 09:30PM |
| Credit: | OpenConnect |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
OpenConnect 'webvpn' Cookie Debugging Output Information Disclosure Vulnerability
OpenConnect is prone to an information-disclosure vulnerability because it fails to properly protect sensitive cookie data in debugging output.
A successful exploit may allow attackers to steal cookie-based authentication credentials; information harvested may aid in further attacks.
Versions prior to OpenConnect 2.26 are vulnerable.
OpenConnect is prone to an information-disclosure vulnerability because it fails to properly protect sensitive cookie data in debugging output.
A successful exploit may allow attackers to steal cookie-based authentication credentials; information harvested may aid in further attacks.
Versions prior to OpenConnect 2.26 are vulnerable.
Exploit / POC
OpenConnect 'webvpn' Cookie Debugging Output Information Disclosure Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to disclose debugging output.
This issue has been publicly demonstrated on the 'openconnect-devel' mailing list.
To exploit this issue, an attacker must entice an unsuspecting user to disclose debugging output.
This issue has been publicly demonstrated on the 'openconnect-devel' mailing list.
Solution / Fix
OpenConnect 'webvpn' Cookie Debugging Output Information Disclosure Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
OpenConnect 'webvpn' Cookie Debugging Output Information Disclosure Vulnerability
References:
References:
- OpenConnect Homepage (OpenConnect)