Описание
process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| openconnect | fixed | 8.02-1.1 | package |
Примечания
http://lists.infradead.org/pipermail/openconnect-devel/2019-September/005412.html
https://github.com/openconnect/openconnect/commit/875f0a65ab73f4fb581ca870fd3a901bd278f8e8
Связанные уязвимости
CVSS3: 9.8
ubuntu
больше 6 лет назад
process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes.
CVSS3: 9.8
nvd
больше 6 лет назад
process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes.