OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to getcertname in gnutls.c.
{ "binaries": [ { "binary_name": "libopenconnect-dev", "binary_version": "7.06-2build2" }, { "binary_name": "libopenconnect5", "binary_version": "7.06-2build2" }, { "binary_name": "openconnect", "binary_version": "7.06-2build2" } ] }
{ "binaries": [ { "binary_name": "libopenconnect-dev", "binary_version": "7.08-3ubuntu0.18.04.2" }, { "binary_name": "libopenconnect5", "binary_version": "7.08-3ubuntu0.18.04.2" }, { "binary_name": "openconnect", "binary_version": "7.08-3ubuntu0.18.04.2" } ] }
{ "binaries": [ { "binary_name": "libopenconnect-dev", "binary_version": "8.05-1" }, { "binary_name": "libopenconnect5", "binary_version": "8.05-1" }, { "binary_name": "openconnect", "binary_version": "8.05-1" } ] }