[prev in list] [next in list] [prev in thread] [next in thread] 

List:       full-disclosure
Subject:    Re: [FD] Cisco AnyConnect elevation of privileges via DMG install script
From:       "Securify B.V." <lists () securify ! nl>
Date:       2015-09-30 15:50:32
Message-ID: 560C04C8.4040405 () securify ! nl
[Download RAW message or body]

------------------------------------------------------------------------
Fix
------------------------------------------------------------------------
Cisco customers with active contracts can obtain updates through the
Software Center at https://software.cisco.com/download/navigator.html.

Cisco has released bug ID CSCuv11947 for registered users, which
contains additional details and an up-to-date list of affected product
versions.


On 23-09-15 19:14, Securify B.V. wrote:
> ------------------------------------------------------------------------
> Cisco AnyConnect elevation of privileges via DMG install script
> ------------------------------------------------------------------------
> Yorick Koster, July 2015
> 
> ------------------------------------------------------------------------
> Abstract
> ------------------------------------------------------------------------
> Cisco AnyConnect Secure Mobility Client for OS X is affected by a
> vulnerability that allows local attackers to mount arbitrary DMG files
> at arbitrary mount points. By exploiting this vulnerability is is
> possible for the attacker to gain root privileges. Cisco reports that a
> similar issue also exists in Cisco AnyConnect Secure Mobility Client for
> Linux.
> 
> ------------------------------------------------------------------------
> See also
> ------------------------------------------------------------------------
> - CVE-2015-6306
> - http://tools.cisco.com/security/center/viewAlert.x?alertId=41135
> 
> ------------------------------------------------------------------------
> Tested version
> ------------------------------------------------------------------------
> This issue was successfully verified on Cisco AnyConnect Secure Mobility
> Client for OS X version 3.1.08009.
> 
> ------------------------------------------------------------------------
> Fix
> ------------------------------------------------------------------------
> There is currently no fix available. Updates are expected to be released
> on September 30, 2015.
> 
> Cisco has released bug ID CSCuv11947 for registered users, which
> contains additional details and an up-to-date list of affected product
> versions.
> 
> ------------------------------------------------------------------------
> Details
> ------------------------------------------------------------------------
> https://www.securify.nl/advisory/SFY20150701/cisco_anyconnect_elevation_of_privileges_via_dmg_install_script.html \
>  

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic