Описание
Security update for openconnect
This update for openconnect fixes the following issues:
Security issue fixed:
- CVE-2020-12105: Fixed the improper handling of negative return values from X509_check_ function calls that might have allowed MITM attacks (bsc#1170452).
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.1
openconnect-7.08-lp151.6.6.1
openconnect-devel-7.08-lp151.6.6.1
openconnect-doc-7.08-lp151.6.6.1
openconnect-lang-7.08-lp151.6.6.1
Ссылки
- E-Mail link for openSUSE-SU-2020:0694-1
- SUSE Security Ratings
- SUSE Bug 1170452
- SUSE CVE CVE-2020-12105 page
Описание
OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.
Затронутые продукты
openSUSE Leap 15.1:openconnect-7.08-lp151.6.6.1
openSUSE Leap 15.1:openconnect-devel-7.08-lp151.6.6.1
openSUSE Leap 15.1:openconnect-doc-7.08-lp151.6.6.1
openSUSE Leap 15.1:openconnect-lang-7.08-lp151.6.6.1
Ссылки
- CVE-2020-12105
- SUSE Bug 1170452