Skip to main content

SonicWALL SSL-VPN Buffer Overflow Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 1 Nov 2010 5859 Views

RISK: Medium Risk

A vulnerability has been identified in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX Control, which could be exploited by remote attackers to compromise a vulnerable system.

The vulnerability is caused due to a boundary error in the "Aventail.EPInstaller" ActiveX control when handling the "Install3rdPartyComponent()" method. This can be exploited to cause a stack-based buffer overflow via specially crafted "CabURL" and "Location" arguments.


Impact

  • Remote Code Execution

System / Technologies affected

  • SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX Control 10.x

Solutions

Update to version 10.5.2 and apply hotfix 3 for version 10.0.5.


Vulnerability Identifier


Source


Related Link