CVE-2013-7098: Critical severity openconnect vulnerability
Published Feb 13, 2020
·Updated
OpenConnect VPN client with GnuTLS before 5.02 contains a heap overflow if MTU is increased on reconnection.
Affected Software
1 affected component
Infradead Openconnect<5.02
Event History
Feb 13, 2020
CVE Published
via MITRE·10:32 PM
Data Sourced
via MITRE·10:32 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of OpenConnect VPN client with GnuTLS?
The vulnerability ID of OpenConnect VPN client with GnuTLS is CVE-2013-7098.
2
What is the title of the vulnerability?
The title of the vulnerability is 'OpenConnect VPN client with GnuTLS before 5.02 contains a heap overflow if MTU is increased on reconnection.'
3
What is the severity of CVE-2013-7098?
The severity of CVE-2013-7098 is critical with a severity value of 9.8.
4
What software is affected by CVE-2013-7098?
OpenConnect VPN client with GnuTLS before version 5.02 is affected by CVE-2013-7098.
5
How can I fix the vulnerability in OpenConnect VPN client with GnuTLS?
To fix the vulnerability, make sure to update OpenConnect VPN client to version 5.02 or later.