|
|||
Rule General Information |
---|
Release Date: | 2013-12-23 | |
Rule Name: | WEB-ACTIVEX SonicWALL SSL VPN End Point Interrogator Installer ActiveX Control code execution | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | There exists a code execution vulnerability in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX controls. Specifically, the vulnerability is due to a format string error in the "epi.dll" library when creating a log message. This can be exploited by assigning a specially crafted string value to affected properties of the ActiveX control. | |
Impact: | Remote code execution | |
Affected OS: | Network Device, Solaris, FreeBSD, Windows, Other Unix, Linux | |
Reference: | SecurityAdvisory:SA41026 KBID:8272 NSOADV-2010-005 |
|
Solutions |
---|
Update vendor's patch. |