This application requires Javascript for optimal performance.

Juniper.JuniperSetupDLL.ActiveX.Control.Buffer.Overflow

Release Date

Aug 20, 2009

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to attack the buffer overflow vulnerability in Juniper SSL-VPN Client. The vulnerability in ActiveX inside JuniperSetupDLL.dll is caused by insufficient checking of user-supplied input for ProductName parameter.

Affected Products

Juniper Networks SSL-VPN Client 0

Recommended Actions

Juniper Networks has released a security alert (PSN-2006-03-013) and patch to fix this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-2086

Reference/s

http://www.securityfocus.com/bid/17712 (BugTraq)

Reference: VID-17628