Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pages that were written during another user's SSL VPN session.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.cisco.com/en/US/products/products_security_advisory09186a0080754f34.shtml | vendor advisory |
http://www.securityfocus.com/bid/20410 | vdb entry |
http://securitytracker.com/id?1017018 | vdb entry |