CVE-2009-4118
01.12.2009, 00:30
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service (service crash and VPN connection loss) via a manual start of cvpnd.exe while the cvpnd service is running.Enginsight
Vendor | Product | Version |
---|---|---|
cisco | vpn_client | 2.0 |
cisco | vpn_client | 3.0 |
cisco | vpn_client | 3.0.5 |
cisco | vpn_client | 3.1 |
cisco | vpn_client | 3.5.1 |
cisco | vpn_client | 3.5.1c:c |
cisco | vpn_client | 3.5.2 |
cisco | vpn_client | 3.6.5:base |
cisco | vpn_client | 4.7.00.0000 |
cisco | vpn_client | 4.8.00.0000 |
cisco | vpn_client | 4.8.00.0440 |
cisco | vpn_client | 4.8.1 |
cisco | vpn_client | 4.8.01:base |
cisco | vpn_client | 4.8.02.0010:base |
cisco | vpn_client | 4.9:base |
cisco | vpn_client | 5.0.00.340:base |
cisco | vpn_client | 5.0.01 |
cisco | vpn_client | 5.0.01.0600:base |
cisco | vpn_client | 5.0.2.0090 |
cisco | vpn_client | 5.0.02.0090:base |
𝑥
= Vulnerable software versions
References