The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer overflow attacks within the five minute timeout period.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Security_agent | Cisco | 3 (including) | 3 (including) |
Security_agent | Cisco | 4.0 (including) | 4.0 (including) |
Security_agent | Cisco | 4.0.1 (including) | 4.0.1 (including) |
Security_agent | Cisco | 4.0.2 (including) | 4.0.2 (including) |
Security_agent | Cisco | 4.0.3 (including) | 4.0.3 (including) |
Stormwatch | Okena | 3.x (including) | 3.x (including) |