Description
Multiple format string vulnerabilities in the configuration file in SonicWALL GLobal VPN Client 3.1.556 and 4.0.0.810 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in the (1) Hostname tag or the (2) name attribute in the Connection tag. NOTE: there might not be any realistic circumstances in which this issue crosses privilege boundaries.
Affected products
- SonicWall / global_vpn_client3.1.556 – 3.1.556
- SonicWall / global_vpn_client4.0.0.810 – 4.0.0.810
References
- MISChttp://www.sec-consult.com/305.html
- MAILING_LISThttp://marc.info/?l=bugtraq&m=119678272603064&w=2
- MISChttp://www.securityfocus.com/bid/26689
- MISChttp://www.securitytracker.com/id?1019038
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2007/4094
- VENDOR_ADVISORYhttp://secunia.com/advisories/27917