Security researcher mu-b at Digit-Labs.org has reported a flaw in Cisco VPN Client 5.x that could be exploited by malicious, local users to cause a denial-of-service attack. The vulnerability, rated as “not critical” by security software vendor Secunia, is caused due to an error when handling certain IOCTLs sent to the IPSec driver (CVPNDRVA.sys), according to an alert on Secunia’s Web site. The flaw could be exploited to cause a memory corruption within the kernel space by sending specially crafted IOCTLs to the affected driver, resulting in a system crash, adds the alert.
The vulnerability is reported in CVPNDRVA.sys version 5.0.02.0090 and there is currently no patch available.
The report comes a day after Cisco released a security advisory warning that its Cisco Unified Communications Manager – formerly CallManager – contains a heap overflow vulnerability in the Certificate Trust List that could allow a hacker to cause a denial-of-service attack or execute arbitrary code. A patch and workarounds are available for that problem on Cisco’s Web site.
More from Cisco Subnet:
* Cisco warns of CallManager heap overflow vulnerability
* Does virtualization spell the end of good DMZ security?
* $137B required by 2010 to close gap between growing demand and broadband access capacity
* Cisco souped up cable modem races at 1Gbps
* Another man pleads guilty to defrauding Cisco SMARTnet
* Insider view on finding stuff fast on cisco.com
* Win an iPod Touch; win a copy of ‘Firewall Fundamentals’ book
Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.
Recent Cisconet blog entries
Network World’s IT Buyer’s Guide: Cisco products




