Security Portal

Intrusion Prevention Service

 
Signature Version: 4.788

 



WEB-ACTIVEX SonicWall SSL-VPN NetExtender ActiveX Control Buffer Overflow
 
Threat Level: High
Release Date: 2011/9/26
 
Category: Buffer Overflow
Signature ID: 1055020
Included In: Full
Affected OS: Windows
 
Description: A stack buffer overflow vulnerability was disclosed in SonicWall SSL-VPN NetExtender. By sending an overly long string to the AddRouteEntry() method located in the NELaunchX.dll (1.0.0.26)Control, an attacker may be able to execute arbitrary code.
 
Impact: Remote code execution
Recommendation: Update vendor's patch.
 
False Positive: None
False Negative: None
 
Additional Information (Links open in new window):
Reference(s): CVE-2007-5603; msf
 

Search the Threat Database
Enter Rule ID or Name