First published: Tue Oct 12 2010(Updated: )
Unspecified vulnerability in OpenConnect before 2.23 allows remote AnyConnect SSL VPN servers to cause a denial of service (application crash) via a 404 HTTP status code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
infradead OpenConnect | =1.40 | |
infradead OpenConnect | =1.00 | |
infradead OpenConnect | =1.30 | |
infradead OpenConnect | =2.00 | |
infradead OpenConnect | =2.21 | |
infradead OpenConnect | <=2.22 | |
infradead OpenConnect | =2.11 | |
infradead OpenConnect | =1.10 | |
infradead OpenConnect | =2.10 | |
infradead OpenConnect | =2.01 | |
infradead OpenConnect | =2.12 | |
infradead OpenConnect | =2.20 | |
infradead OpenConnect | =1.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3903 has a severity rating that can lead to denial of service due to application crashes.
To fix CVE-2010-3903, upgrade to a version of OpenConnect beyond 2.22.
CVE-2010-3903 affects OpenConnect versions 1.00, 1.10, 1.20, 1.30, 1.40, 2.00, 2.10, 2.11, 2.12, 2.20, 2.21, and all versions up to 2.22.
Yes, CVE-2010-3903 can be exploited remotely by sending a specific 404 HTTP status code from an AnyConnect SSL VPN server.
CVE-2010-3903 can cause OpenConnect applications to crash, leading to a denial of service for users.