CVE-2012-6128
EPSS 0.97%openconnect - buffer overflow
Published: 2/24/2013Modified: 4/28/2026
Also known as:DEBIAN-CVE-2012-6128
Description
Multiple stack-based buffer overflows in http.c in OpenConnect before 4.08 allow remote VPN gateways to cause a denial of service (application crash) via a long (1) hostname, (2) path, or (3) cookie list in a response.
Affected packages (2)
- Debian/openconnectfrom 0, < 3.20-3
- Debian/openconnectfrom 0, < 2.25-0.1+squeeze2