CVE-2009-5007

Cisco AnyConnect SSL VPN Trial Client - Arbitrary File Overwrite via Symlink Attack

Title source: llm
STIX 2.1

Description

The Cisco trial client on Linux for Cisco AnyConnect SSL VPN allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42093
Various Sources x_refsource_misc
http://www.infradead.org/openconnect.html

Scores

EPSS 0.0034
EPSS Percentile 25.3%

Details

CWE
CWE-59
Status published
Products (1)
cisco/anyconnect_ssl_vpn
Published Oct 14, 2010
Tracked Since Feb 18, 2026