Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-12105

Опубликовано: 23 апр. 2020
Источник: debian

Описание

OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openconnectunfixedpackage
openconnectnot-affectedjessiepackage

Примечания

  • https://gitlab.com/openconnect/openconnect/-/merge_requests/96

  • Only an issue if building with OpenSSL, where Debian binary packages use

  • GnuTLS.

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 6 лет назад

OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.

CVSS3: 5.9
nvd
почти 6 лет назад

OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.

suse-cvrf
больше 5 лет назад

Security update for openconnect

suse-cvrf
больше 5 лет назад

Security update for openconnect

suse-cvrf
больше 5 лет назад

Security update for openconnect