Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8w9v-97h7-m2j5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).

EPSS

Процентиль: 69%
0.00616
Низкий

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 6 лет назад

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).

CVSS3: 5.3
nvd
почти 6 лет назад

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).

CVSS3: 5.3
debian
почти 6 лет назад

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL ...

suse-cvrf
почти 6 лет назад

Security update for openfortivpn

EPSS

Процентиль: 69%
0.00616
Низкий

Дефекты

CWE-295