36332Third-party advisory
http://secunia.com/advisories/36332 CVE-2009-2918
TheGreenBow VPN Client - 'tgbvpn.sys' Local Denial of Service
Record summary
CVE-2009-2918 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
The tgbvpn.sys driver in TheGreenBow IPSec VPN Client 4.61.003 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted request to the 0x80000034 IOCTL, probably involving an input or output buffer size of 0.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTheGreenBow VPN Client - 'tgbvpn.sys' Local Denial of ServiceExploitDB exploitby EvilcryNot analyzed1 file
References
520090817 TheGreenBow VPN Client tgbvpn.sys DoS and Potential Localmailing list
http://www.securityfocus.com/archive/1/505816/100/0/threaded ADV-2009-2294vdb entry
http://www.vupen.com/english/advisories/2009/2294 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-2918 evilfingers.com
https://www.evilfingers.com/advisory/Advisory/TheGreenBow_VPN_Client_tgbvpn.sys_DoS.php