SB2020070210 - Link following in Cisco AnyConnect Secure Mobility Client for Mac OS
Published: July 2, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Link following (CVE-ID: CVE-2020-3432)
The vulnerability allows a local user to corrupt the content of any file in the filesystem.
The vulnerability exists due to the incorrect handling of directory paths in the uninstaller component. A local user can create a symbolic link (symlink) to a target file on a specific path and corrupt the contents of the file, leading to denial of service (DoS) condition.
Remediation
Install update from vendor's website.