Multiple vulnerabilities exist in the Cisco Virtual Private Network (VPN) 5000 Client software. These vulnerabilities are documented as Cisco bug ID CSCdx17109 and CSCdy20065. There are some workarounds available to mitigate the effects of these vulnerabilities. This advisory will be posted at http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020918-vpn5k-vulnerability.
Multiple vulnerabilities exist in the Cisco Virtual Private Network (VPN) 5000 Client software. These vulnerabilities are documented as Cisco bug ID CSCdx17109 and CSCdy20065. There are some workarounds available to mitigate the effects of these vulnerabilities.
This advisory will be posted at http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020918-vpn5k-vulnerability.
This section provides details on affected products.
DDTS - Description |
Affected Releases |
---|---|
CSCdx17109 - MAC OS VPN 5000 Client password vulnerability |
MAC OS VPN 5000 Client releases earlier than 5.2.2 |
CSCdy20065 - Linux and Solaris VPN 5000 Client buffer overflow vulnerability |
|
The Cisco VPN 3000 client and the Cisco VPN client are not affected.
No other Cisco products are currently known to be affected by these vulnerabilities.
The VPN Client software program on a remote workstation, communicating with a Cisco VPN device on an enterprise network or with a service provider, creates a secure connection over the Internet. Through this connection you can access a private network as if you were an onsite user.
DDTS - Description |
Details |
---|---|
CSCdx17109 - MAC OS VPN 5000 Client password vulnerability |
When saving the "Default Connection" in the resource fork of the preferences file, the client saves the entire contents of the data structure that represents the "Default Connection" which includes the most recently used login password. This password can be read in plain text using the ResEdit tool. This occurs regardless of whether "SaveSecrets" is enabled or disabled, and regardless of whether you encrypt passwords or not. |
CSCdy20065 - Linux and Solaris VPN 5000 Client buffer overflow vulnerability |
Two buffer overflow issues exist in the VPN 5000 Client for Linux and Solaris. One in the close_tunnel binary and one in the open_tunnel binary. To exploit the vulnerability one has to be logged in on the workstation. The buffer overflows could be locally exploited to gain root privileges on the workstation. |
These vulnerabilities are documented in the Cisco Bug Toolkit as Bug IDs CSCdx17109 and CSCdy20065, and can be viewed after September 19, 2002 at 1500 UTC. To access this tool, you must be a registered user and you must be logged in.
Workarounds are described in this table.
DDTS - Description |
Workaround / Mitigation Techniques |
---|---|
CSCdx17109 - MAC OS VPN 5000 Client password vulnerability |
|
CSCdy20065 - Linux and Solaris VPN 5000 Client buffer overflow vulnerability |
There is no workaround. |
The Cisco PSIRT recommends that affected users upgrade to a fixed software version of code.
When considering software upgrades, also consult http://www.cisco.com/go/psirt and any subsequent advisories to determine exposure and a complete upgrade solution.
In all cases, customers should exercise caution to be certain the devices to be upgraded contain sufficient memory and that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, contact the Cisco Technical Assistance Center ("TAC") or your contracted maintenance provider for assistance.
DDTS - Description |
Affected Releases |
---|---|
CSCdx17109 - MAC OS VPN 5000 Client password vulnerability |
MAC OS VPN 5000 Client release 5.2.2 or later |
CSCdy20065 - Linux and Solaris VPN 5000 Client buffer overflow vulnerability |
|
The procedure to upgrade to the fixed software version is detailed at http://www.cisco.com/univercd/cc/td/doc/product/aggr/vpn5000/client/.
The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities described in this advisory.
Cisco Bug ID CSCdx17109 was reported to Cisco by a customer. Cisco Bug ID CSCdy20065 was reported to Cisco by Niels Heinen of Ubizen.
To learn about Cisco security vulnerability disclosure policies and publications, see the Security Vulnerability Policy. This document also contains instructions for obtaining fixed software and receiving security vulnerability information from Cisco.
Revision 1.0 |
2002-September-18 |
Initial public release. |
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.
A stand-alone copy or paraphrase of the text of this document that omits the distribution URL is an uncontrolled copy, and may lack important information or contain factual errors. The information in this document is intended for end-users of Cisco products.