CVE-2009-3861: Buffer Overflow
Published Nov 4, 2009
·Updated
Stack-based buffer overflow in SafeNet SoftRemote 10.8.5 (Build 2) and 10.3.5 (Build 6), and possibly other versions before 10.8.9, allows local users to execute arbitrary code via a long string in a (1) TREENAME or (2) GROUPNAME Policy file (spd).
Affected Software
16 affected components
Safenet-inc Softremote=1.9.0
Safenet-inc Softremote<=10.8.8
Safenet-inc Softremote=10.8.7
Safenet-inc Softremote=10.8.0
Safenet-inc Softremote=10.8.3
Safenet-inc Softremote=1.7.7
Safenet-inc Softremote=10.3.5
Safenet-inc Softremote=10.7.7
Safenet-inc Softremote=10.8.6
Safenet-inc Softremote=1.7.2
Safenet-inc Softremote=1.7.1
Safenet-inc Softremote=10.8.5
Safenet-inc Softremote=1.8.1
Safenet-inc Softremote=10.8.2
Safenet-inc Softremote=10.8.1
Safenet-inc Softremote=10.8.4
Event History
Nov 4, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3861?
CVE-2009-3861 is rated as a high severity vulnerability due to the potential for local users to execute arbitrary code.
2
How do I fix CVE-2009-3861?
To fix CVE-2009-3861, update SafeNet SoftRemote to version 10.8.9 or later.
3
Which versions of SafeNet SoftRemote are affected by CVE-2009-3861?
SafeNet SoftRemote versions 10.8.5, 10.3.5, and possibly earlier are affected by CVE-2009-3861.
4
Can CVE-2009-3861 be exploited remotely?
No, CVE-2009-3861 requires local access to the system to be exploited.
5
What type of exploitation is possible with CVE-2009-3861?
CVE-2009-3861 allows for a stack-based buffer overflow resulting in arbitrary code execution.