Multiple stack-based buffer overflows in http.c in OpenConnect before 4.08 allow remote VPN gateways to cause a denial of service (application crash) via a long (1) hostname, (2) path, or (3) cookie list in a response.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openconnect | Jul 30, 2024 | Feb 24, 2013 |
| Gentoo Linux | — | Upgrade net-misc/openconnect. | Oct 30, 2017 | Feb 24, 2013 |
| Suse | — | Upgrade openconnect-develUpgrade openconnectUpgrade openconnect-lang | Dec 12, 2013 | Jun 27, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub