CVE-2020-7043: Critical severity Openfortivpn Project Openfortivpn vulnerability
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7043?
The severity of CVE-2020-7043 is critical with a CVSS score of 9.1.
How does CVE-2020-7043 affect openfortivpn?
CVE-2020-7043 affects openfortivpn version 1.11.0 up to, but not including, version 1.12.0.
Which OpenSSL versions are vulnerable to CVE-2020-7043?
OpenSSL versions before 1.0.2 are vulnerable to CVE-2020-7043.
How can I fix CVE-2020-7043 in openfortivpn?
To fix CVE-2020-7043 in openfortivpn, upgrade to version 1.12.0 or later.
Are there any references available for CVE-2020-7043?
Yes, you can find references for CVE-2020-7043 at the following links: - http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00009.html - http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00011.html - https://github.com/adrienverge/openfortivpn/commit/6328a070ddaab16faaf008cb9a8a62439c30f2a8