CVE-2008-0324: Medium severity cisco vpn client vulnerability
Published Jan 17, 2008
·Updated
Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOCTL with a small size value, which triggers memory corruption.
Affected Software
1 affected component
Cisco VPN Client=5.0.2.0090
Event History
Jan 17, 2008
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0324?
The severity of CVE-2008-0324 is rated as moderate, due to its potential for causing denial of service.
2
How do I fix CVE-2008-0324?
To fix CVE-2008-0324, it is recommended to update to a patched version of the Cisco VPN Client.
3
What impact does CVE-2008-0324 have on my system?
CVE-2008-0324 can lead to a denial of service by crashing the Cisco VPN Client due to memory corruption.
4
Who is affected by CVE-2008-0324?
Local users on systems running Cisco VPN Client version 5.0.2.0090 are affected by CVE-2008-0324.
5
What components are involved in CVE-2008-0324?
CVE-2008-0324 involves the IPSec driver (CVPNDRVA.sys) of the Cisco VPN Client.