BSA-2020-926
21603
13 March 2020
13 March 2020
Closed
Low
5.3
Yes
CVE-2020-7041, CVE-2020-7042, CVE-2020-7043
Summary Security Advisory ID : BSA-2020-926 Component : openfortivpn Revision : 1.0: Final
tunnel.c mishandles certificate validation in openfortivpn 1.11.0 due to multiples issues.
CVE-2020-7041
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.
CVE-2020-7042
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted.
CVE-2020-7043
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.
Affected Products
No Brocade Fiber Channel Products from Broadcom are currently known to be affected by this vulnerability.
Revision History
|
Version |
Change |
Date |
|---|---|---|
|
1.0 |
Initial Publication |
March 13, 2020 |