CVE-2007-5603: Buffer Overflow
Published Nov 5, 2007
·Updated
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remote attackers to execute arbitrary code via a long string in the second argument to the AddRouteEntry method.
Affected Software
2 affected components
SonicWall SSL VPN<=2.1
SonicWall SSL VPN<=2.5
Event History
Nov 5, 2007
CVE Published
06:46 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5603?
CVE-2007-5603 has been assigned a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2007-5603?
To fix CVE-2007-5603, upgrade the SonicWall SSL-VPN to version 2.1.0.51 or 2.5.0.56 or later.
3
What products are affected by CVE-2007-5603?
CVE-2007-5603 affects SonicWall SSL-VPN versions before 2.1.0.51 and 2.5.x before 2.5.0.56.
4
Can CVE-2007-5603 be exploited remotely?
Yes, CVE-2007-5603 can be exploited remotely by attackers through specially crafted input.
5
What type of vulnerability is CVE-2007-5603?
CVE-2007-5603 is a stack-based buffer overflow vulnerability.