9.8
CVSSv3

CVE-2020-12823

Published: 12/05/2020 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

infradead openconnect 8.09

fedoraproject fedora 30

fedoraproject fedora 31

fedoraproject fedora 32

debian debian linux 8.0

opensuse leap 15.1

opensuse leap 15.2

Vendor Advisories

Debian Bug report logs - #960620 openconnect: buffer overflow in certificate handling (CVE-2020-12823) Package: openconnect; Maintainer for openconnect is Mike Miller <mtmiller@debianorg>; Source for openconnect is src:openconnect (PTS, buildd, popcon) Reported by: Luca Boccassi <bluca@debianorg> Date: Thu, 14 May ...
Severity Unknown Remote Unknown Type Unknown Description AVG-1157 openconnect 1:805-1 Unknown Vulnerable ...