-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Cisco Security Advisory: Cisco ASA Clientless SSL VPN CIFS Heap Overflow 
Vulnerability

Advisory ID: cisco-sa-20170208-asa

Revision 1.0

For Public Release  2017 February 8 16:00  GMT (UTC)

+---------------------------------------------------------------------

Summary
=======

A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL 
VPN functionality of Cisco ASA Software could allow an authenticated, remote 
attacker to cause a heap overflow.

The vulnerability is due to insufficient validation of user supplied input. An 
attacker could exploit this vulnerability by sending a crafted URL to the 
affected system. An exploit could allow the remote attacker to cause a reload 
of the affected system or potentially execute code.

Note: Only traffic directed to the affected system can be used to exploit this 
vulnerability. This vulnerability affects systems configured in routed firewall 
mode only and in single or multiple context mode. This vulnerability can be 
triggered by IPv4 or IPv6 traffic. A valid TCP connection is needed to perform 
the attack. The attacker needs to have valid credentials to log in to the 
Clientless SSL VPN portal.

Cisco has released software updates that address this vulnerability. 
Workarounds that mitigate this vulnerability are available. This advisory is 
available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170208-asa








-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJYmzrBAAoJEK89gD3EAJB5EnUQAJvwO4o8k7USSiKn6WOoL3e6
+xm9hU+un1C3En1VjHE+l64c5/INlNgMdqxU1ZpTIV/7azsgL75Y98XHCGRcdpNT
8eZkVSFdkskopqTzPhccHg98uP2PiKFbBYXiFph5hoVzzUEjfTnTdR+f4lqomGwp
F4rgNpvfU44N5ytdR/wK/pOcmqvcqYA4d9FKHsjb/3uQqAqWoX6TlWWruAlu4kUt
0T/mPUvD9heTKjzSFIk58P2iUqpkSf33TxhAnwhv1UBsjZvOaXUH7kwEzfJjwJI8
Dife+6lOHzkSZJ5g/m/TDoNxDOu5DybrudMKf3KmjCPBxuh7L7/pEu1PmNHX3Gn/
8W+dsKWIVCPI0ZqkGOgkDpkvdmKXskCH9gCtuaUq4B3teSaESulz5rHy9rvqieHH
cwauoiNS8tonacBPOSwIAbCPFCiGM2MUsYXH+08IMbI+cGuRuTLyQCLLYKVG+ArE
Pmshi9WbqrNJ4RtSaQ15jva5rkBjVuy3xhkt5yyN1GEQRr7MlNJBs2h/8u6/yKgo
kr2WcPvtP4vcNZeC2ThKTmb09h6L4JzK67JJMZaORnIPigdyiY2vG7KvU03Q+HHI
XbTeH/dgDTm6EOT7575/I8jegwGAXFqMZGxDyBIutJHviw/eJCjqdenrWZn+1amn
i3VqKIeVzO2M8CINO026
=XUkg
-----END PGP SIGNATURE-----

Reply via email to