#VU28192 Buffer overflow in OpenConnect VPN Client - CVE-2020-12823
Published: May 23, 2020
OpenConnect VPN Client
OpenConnect
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary within the get_cert_name() function in gnutls.c. A remote attacker can trick the victim to connect to a malicious VPN server, trigger buffer overflow and crash the client or execute arbitrary code on the system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.