CVE-2020-7043
27.02.2020, 18:15
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.Enginsight
Vendor | Product | Version |
---|---|---|
openfortivpn_project | openfortivpn | 𝑥 < 1.12.0 |
opensuse | backports_sle | 15.0:sp1 |
opensuse | leap | 15.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References