Title : SonicWALL SSL-VPN ActiveX Controls Multiple Remote Vulnerabilities VUPEN ID : VUPEN/ADV-2007-3696 CVE ID : CVE-2007-5603 - CVE-2007-5814 - CVE-2007-5815
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-11-02
Technical Description
Multiple vulnerabilities have been identified in SonicWALL SSL-VPN, which could be exploited by attackers to cause a denial of service or take complete control of an affected system.
The first issue is caused by a design error in the WebCacheCleaner ActiveX control that does not restrict access to the "FileDelete()" method, which could be exploited by attackers to delete rbitrary files from a vulnerable system.
The second vulnerability is caused by buffer overflow errors in the NELaunchCtrl ActiveX control when processing malformed data passed to the "AddRouteEntry()" method or to the "serverAddress", "sessionId", "clientIPLower", "clientIPHigher", "userName", "domainName" and "dnsSuffix" properties, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.