CVE-2020-8249: Buffer Overflow in Pulse Secure VPN Linux Client
CVE-2020-8249: Buffer Overflow in Pulse Secure VPN Linux Client The root SUID executable pulsesvc, has a function “do_upload” that unsafely calls a “sprintf” which can result in a buffer overflow Because the “sprintf” writes the values on the stack, if a big enough string is passed to it, then it can result in the overwrite of the legitimate