Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-7043

Опубликовано: 27 фев. 2020
Источник: debian

Описание

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openfortivpnfixed1.12.0-1package

Примечания

  • https://github.com/adrienverge/openfortivpn/issues/536

  • https://github.com/adrienverge/openfortivpn/commit/6328a070ddaab16faaf008cb9a8a62439c30f2a8

  • No version of openfortivpn was shipped with OpenSSL < 1.0.2, marking as unimportant

Связанные уязвимости

CVSS3: 9.1
ubuntu
почти 6 лет назад

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.

CVSS3: 9.1
nvd
почти 6 лет назад

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.

CVSS3: 9.1
github
больше 3 лет назад

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider &#39;\0&#39; characters, as demonstrated by a good.example.com\x00evil.example.com attack.

suse-cvrf
почти 6 лет назад

Security update for openfortivpn