Cisco AnyConnect Secure Mobility Client for Linux and Mac OS X Privilege Escalation Vulnerability
|
Información sobre el sistema
|
|
|
Software afectado |
Cisco |
Descripción
|
A vulnerability in the code responsible for the self-updating feature of Cisco AnyConnect Secure Mobility Client for Linux and the Cisco AnyConnect Secure Mobility Client for Mac OS X could allow an authenticated, local attacker to execute an arbitrary executable file of its choosing with privileges equivalent to the Linux or Mac OS X root account.The vulnerability is due to lack of checks in the code for the path and filename of the file being installed. An attacker could exploit this
More info:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20150923-CVE-2015-6306?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20AnyConnect%20Secure%20Mobility%20Client%20for%20Linux%20and% |
Identificadores estándar
|
Propiedad |
Valor |
CVE |
|