CVE-2012-3291: Heap-based buffer overflow in OpenConnect

Bug #1013946 reported by Karma Dorje
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
openconnect (Debian)
Fix Released
Unknown
openconnect (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

CVE-2012-3291 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3291):
  Heap-based buffer overflow in OpenConnect 3.18 allows remote servers to
  cause a denial of service via a crafted greeting banner.

CVE References

Karma Dorje (taaroa)
affects: openconnect → openconnect (Ubuntu)
Changed in openconnect (Debian):
status: Unknown → New
Changed in openconnect (Debian):
status: New → Fix Released
Karma Dorje (taaroa)
security vulnerability: yes → no
visibility: private → public
Karma Dorje (taaroa)
security vulnerability: no → yes
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Quantal now has 3.20-2.

Changed in openconnect (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.