First published: Tue Oct 12 2010(Updated: )
The Cisco trial client on Linux for Cisco AnyConnect SSL VPN allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco AnyConnect Secure |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-5007 is classified as a high severity vulnerability due to its potential to allow local users to exploit a symlink attack to overwrite arbitrary files.
To fix CVE-2009-5007, ensure that you do not have the affected Cisco AnyConnect SSL VPN trial client installed or apply any available patches from Cisco.
CVE-2009-5007 affects local users of the Cisco AnyConnect SSL VPN trial client on Linux.
CVE-2009-5007 is associated with a symlink attack which allows local users to overwrite arbitrary files.
No, CVE-2009-5007 is not a remote vulnerability; it requires local user access to exploit.