Release date:
Updated on:
Affected Systems:
Infradead OpenConnect VPN Gateway <4.08
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57884
CVE (CAN) ID: CVE-2012-6128
OpenConnect is the client of Cisco AnyConnect ssl vpn.
The implementation of OpenConnect has the stack buffer overflow vulnerability. By sending a specially crafted host name, path, or cookie list from the VPN gateway, remote attackers can exploit this vulnerability to cause buffer overflow, arbitrary code execution on the system, or application crash.
<* Source: Kevin Cernekee
Link: http://xforce.iss.net/xforce/xfdb/82058
Http://www.openwall.com/lists/oss-security/2013/02/12/7
Https://bugzilla.redhat.com/show_bug.cgi? Id = 910333
Http://packetstormsecurity.com/files/cve/CVE-2012-6128
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Infradead
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.infradead.org/openconnect/index.html