CVE-2020-12105
23.04.2020, 17:15
OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| infradead | openconnect | 𝑥 ≤ 8.08 |
| opensuse | leap | 15.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libopenconnect5 |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| openconnect |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| openconnect-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| openconnect-lang |
|
Common Weakness Enumeration
References