Lucene search

K
cve[email protected]CVE-2009-3861
HistoryNov 04, 2009 - 5:30 p.m.

CVE-2009-3861

2009-11-0417:30:00
CWE-119
web.nvd.nist.gov
28
cve-2009-3861
stack-based buffer overflow
safenet softremote
arbitrary code execution
nvd
security vulnerability

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

High

0.881 High

EPSS

Percentile

98.7%

Stack-based buffer overflow in SafeNet SoftRemote 10.8.5 (Build 2) and 10.3.5 (Build 6), and possibly other versions before 10.8.9, allows local users to execute arbitrary code via a long string in a (1) TREENAME or (2) GROUPNAME Policy file (spd).

Affected configurations

NVD
Node
safenet-incsoftremoteRange≀10.8.8
OR
safenet-incsoftremoteMatch1.7.1
OR
safenet-incsoftremoteMatch1.7.2
OR
safenet-incsoftremoteMatch1.7.7
OR
safenet-incsoftremoteMatch1.8.1
OR
safenet-incsoftremoteMatch1.9.0
OR
safenet-incsoftremoteMatch10.3.5
OR
safenet-incsoftremoteMatch10.7.7
OR
safenet-incsoftremoteMatch10.8.0
OR
safenet-incsoftremoteMatch10.8.1
OR
safenet-incsoftremoteMatch10.8.2
OR
safenet-incsoftremoteMatch10.8.3
OR
safenet-incsoftremoteMatch10.8.4
OR
safenet-incsoftremoteMatch10.8.5
OR
safenet-incsoftremoteMatch10.8.6
OR
safenet-incsoftremoteMatch10.8.7

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

High

0.881 High

EPSS

Percentile

98.7%