CVE-2020-12823
9.8
CRITICAL · CVSS 3.1 · EPSS 4.7% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.74% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-120 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-05-12 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| debian | debian linux |
| fedoraproject | fedora |
| infradead | openconnect |
| opensuse | leap |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00039.html
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00056.html
- https://bugs.gentoo.org/721570
- https://gitlab.com/openconnect/openconnect/-/merge_requests/108
- https://lists.debian.org/debian-lts-announce/2020/05/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/25MFX4AZE7RDCUWOL4ZOE73YBOPUMQDX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AYSXLXAPXD2T73T6JMHI5G2WP7KHAGMN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEVTIH5UFX35CC7MVSYBGRM3D66ACFD5/
- https://security.gentoo.org/glsa/202006-15
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00039.html
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00056.html
- https://bugs.gentoo.org/721570
- https://gitlab.com/openconnect/openconnect/-/merge_requests/108
- https://lists.debian.org/debian-lts-announce/2020/05/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/25MFX4AZE7RDCUWOL4ZOE73YBOPUMQDX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AYSXLXAPXD2T73T6JMHI5G2WP7KHAGMN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEVTIH5UFX35CC7MVSYBGRM3D66ACFD5/
- https://security.gentoo.org/glsa/202006-15
→ the Explorer · watch your stack · NVD