An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "30"
},
{
"last_affected": "30"
},
{
"introduced": "31"
},
{
"last_affected": "31"
},
{
"introduced": "32"
},
{
"last_affected": "32"
}
],
"source": "CPE_STRING",
"vendor_product": "fedoraproject:fedora"
},
{
"cpes": [
"cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "15.0-sp1"
},
{
"last_affected": "15.0-sp1"
}
],
"source": "CPE_STRING",
"vendor_product": "opensuse:backports_sle"
},
{
"cpes": [
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "15.1"
},
{
"last_affected": "15.1"
}
],
"source": "CPE_STRING",
"vendor_product": "opensuse:leap"
}
]
}{
"cpe": "cpe:2.3:a:openfortivpn_project:openfortivpn:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.12.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-7042.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"283993573798252670453987687364804281647",
"274844904252654247726432834330319061935",
"112562871745171916936322649166284259591",
"17798813236066237521886087447635982369",
"2418362587896680329337858234838332300",
"109426978569026790148195875681155806346",
"164160928021241801951192137959973253490",
"289510098859083578787605135355407124387",
"258380727189941271346228600724644525725",
"25863080627499099625509319637019956460"
],
"threshold": 0.9
},
"id": "CVE-2020-7042-6fb1fe2a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/adrienverge/openfortivpn/commit/9eee997d599a89492281fc7ffdd79d88cd61afc3",
"target": {
"file": "src/tunnel.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "229937577464691850782465159833446126831",
"length": 2386
},
"id": "CVE-2020-7042-975f888f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/adrienverge/openfortivpn/commit/9eee997d599a89492281fc7ffdd79d88cd61afc3",
"target": {
"file": "src/tunnel.c",
"function": "ssl_verify_cert"
}
}
]
"2026-07-09T00:12:10Z"