SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

TheGreenBow VPN Client Local Stack Overflow Vulnerability


Arrow  SecurityAlert : 6977
Arrow  CVE : CVE-2010-0392
Arrow  CWE : CWE-119
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Victim interaction required : Yes
Arrow  Exploit Available : No
Arrow  Credit : SoS
Arrow  Published : 28.01.2010

Arrow  Affected Software : thegreenbow:ipsec_vpn_client:4.51.001
thegreenbow:ipsec_vpn_client:4.65.003



Arrow  Advisory Content :  

TheGreenBow VPN Client Local Stack Overflow Vulnerability - Security
Advisory - SOS-10-001

Release Date. 21-Jan-2010
Vendor Notification Date. 11-Dec-2009
Product. TheGreenBow VPN Client
Platform. Microsoft Windows
Affected versions. 4.65.003, 4.51.001 verified and
possibly others.
Severity Rating. High
Impact. System access
Attack Vector. Local
Solution Status. Vendor patch
CVE reference. Not yet assigned

Details.
TheGreenBow is an IPsec VPN client that sets up a secure channel
for data transport.

TheGreenBow VPN Client is vulnerable to a local stack based buffer
overflow, which can lead to the compromise of a vulnerable system.

The vulnerability is caused due to a boundary error when processing
certain sections of tgb (policy) files. Passing an overly long
string to "OpenScriptAfterUp" will trigger the overflow.

Successful exploitation results in the execution of arbitrary code.

Solution.
A patch is available from the vendor (unverified) and will be
included in the next release.

Discovered by.
Brett Gervasoni from SOS Labs.
About us.
Sense of Security is a leading provider of information security and risk
management solutions. Our team has expert skills in assessment and
assurance, strategy and architecture, and deployment through to ongoing
management. We are Australia's premier application penetration testing firm

and trusted IT security advisor to many of the countries largest
organisations.

Sense of Security Pty Ltd

Level 3, 66 King St
Sydney NSW 2000
AUSTRALIA

T: +61 (0)2 9290 4444
F: +61 (0)2 9290 4455
W: http://www.senseofsecurity.com.au/consulting/penetration-testing
E: info (at) senseofsecurity.com (dot) au [email concealed]
Twitter: ITsecurityAU

The latest version of this advisory can be found at:

http://www.senseofsecurity.com.au/advisories/SOS-10-001.pdf

Other Sense of Security advisories can be found at:

http://www.senseofsecurity.com.au/research/it-security-advisories.php



Arrow  References :

http://www.thegreenbow.com/download.php?id=1000150
http://www.senseofsecurity.com.au/advisories/SOS-10-001
http://xforce.iss.net/xforce/xfdb/55793
http://www.securityfocus.com/archive/1/archive/1/509091/100/0/threaded
http://secunia.com/advisories/38262
http://osvdb.org/61866




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.