7.8
CVSSv2

CVE-2012-3291

Published: 07/06/2012 Updated: 05/01/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Heap-based buffer overflow in OpenConnect 3.18 allows remote servers to cause a denial of service via a crafted greeting banner.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

infradead openconnect 3.15

infradead openconnect 3.14

infradead openconnect 2.26

infradead openconnect 2.25

infradead openconnect 2.11

infradead openconnect 2.10

infradead openconnect 2.01

infradead openconnect

infradead openconnect 3.16

infradead openconnect 3.01

infradead openconnect 3.00

infradead openconnect 2.20

infradead openconnect 2.12

infradead openconnect 1.10

infradead openconnect 1.00

infradead openconnect 3.13

infradead openconnect 3.12

infradead openconnect 2.24

infradead openconnect 2.23

infradead openconnect 2.00

infradead openconnect 1.40

infradead openconnect 3.11

infradead openconnect 3.02

infradead openconnect 2.22

infradead openconnect 2.21

infradead openconnect 1.30

infradead openconnect 1.20

Vendor Advisories

Debian Bug report logs - #677594 CVE-2012-3291: Heap-based buffer overflow in OpenConnect Package: openconnect; Maintainer for openconnect is Mike Miller <mtmiller@debianorg>; Source for openconnect is src:openconnect (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Fri, 15 Jun 2012 08:15:01 UTC ...
A buffer overflow was discovered in OpenConnect, a client for the Cisco AnyConnect VPN, which could result in denial of service For the stable distribution (squeeze), this problem has been fixed in version 225-01+squeeze1 For the unstable distribution (sid), this problem has been fixed in version 318-1 We recommend that you upgrade your openc ...