CVE-2020-7042
27.02.2020, 18:15
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).Enginsight
| Vendor | Product | Version |
|---|---|---|
| openfortivpn_project | openfortivpn | 𝑥 < 1.12.0 |
| opensuse | backports_sle | 15.0:sp1 |
| opensuse | leap | 15.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References