Exploitation Summary
EIP tracks 1 public exploit for CVE-2002-1447. PoCs published by methodic.
AI-analyzed exploit summary This exploit leverages a buffer overflow in Cisco VPN Client 3.5.1 for Linux by passing an oversized profile name to the suid root binary, leading to local privilege escalation. The shellcode executes /tmp/xx, a helper binary that spawns a root shell.
Description
Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name in a connect argument.
Exploits (1)
This exploit leverages a buffer overflow in Cisco VPN Client 3.5.1 for Linux by passing an oversized profile name to the suid root binary, leading to local privilege escalation. The shellcode executes /tmp/xx, a helper binary that spawns a root shell.