CVE-2020-8249
HIGHPulse Secure Desktop Client (Linux) < 9.1R9 - Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-8249. PoCs published by mbadanoiu.
AI-analyzed exploit summary The repository provides a technical writeup for CVE-2020-8249, detailing a buffer overflow vulnerability in the Pulse Secure VPN Linux client's 'pulsesvc' SUID executable. The exploit involves overwriting the return address via an unsafe 'sprintf' call in the 'do_upload' function, but the actual PoC is referenced in an external PDF.
Description
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to perform buffer overflow.
Exploits (1)
The repository provides a technical writeup for CVE-2020-8249, detailing a buffer overflow vulnerability in the Pulse Secure VPN Linux client's 'pulsesvc' SUID executable. The exploit involves overwriting the return address via an unsafe 'sprintf' call in the 'do_upload' function, but the actual PoC is referenced in an external PDF.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H