First published: Thu Jun 07 2012(Updated: )
Heap-based buffer overflow in OpenConnect 3.18 allows remote servers to cause a denial of service via a crafted greeting banner.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
infradead OpenConnect | <=3.17 | |
infradead OpenConnect | =1.00 | |
infradead OpenConnect | =1.10 | |
infradead OpenConnect | =1.20 | |
infradead OpenConnect | =1.30 | |
infradead OpenConnect | =1.40 | |
infradead OpenConnect | =2.00 | |
infradead OpenConnect | =2.01 | |
infradead OpenConnect | =2.10 | |
infradead OpenConnect | =2.11 | |
infradead OpenConnect | =2.12 | |
infradead OpenConnect | =2.20 | |
infradead OpenConnect | =2.21 | |
infradead OpenConnect | =2.22 | |
infradead OpenConnect | =2.23 | |
infradead OpenConnect | =2.24 | |
infradead OpenConnect | =2.25 | |
infradead OpenConnect | =2.26 | |
infradead OpenConnect | =3.00 | |
infradead OpenConnect | =3.01 | |
infradead OpenConnect | =3.02 | |
infradead OpenConnect | =3.11 | |
infradead OpenConnect | =3.12 | |
infradead OpenConnect | =3.13 | |
infradead OpenConnect | =3.14 | |
infradead OpenConnect | =3.15 | |
infradead OpenConnect | =3.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3291 has a medium severity rating due to its potential to cause denial of service.
To fix CVE-2012-3291, users should upgrade to OpenConnect version 3.18 or later.
The impact of CVE-2012-3291 can lead to a denial of service when remote servers send a crafted greeting banner.
CVE-2012-3291 affects OpenConnect versions up to and including 3.17.
Yes, CVE-2012-3291 is a remote vulnerability that allows attackers to exploit the issue from a distance.