Vulnerability Description
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openfortivpn Project | Openfortivpn | < 1.12.0 |
| Openssl | Openssl | < 1.0.2 |
| Fedoraproject | Fedora | 30 |
| Opensuse | Backports Sle | 15.0 |
| Opensuse | Leap | 15.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00009.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00011.htmlMailing ListThird Party Advisory
- https://github.com/adrienverge/openfortivpn/commit/6328a070ddaab16faaf008cb9a8a6PatchThird Party Advisory
- https://github.com/adrienverge/openfortivpn/commit/cd9368c6a1b4ef91d77bb3fdbe2e5PatchThird Party Advisory
- https://github.com/adrienverge/openfortivpn/issues/536Issue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00009.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00011.htmlMailing ListThird Party Advisory
- https://github.com/adrienverge/openfortivpn/commit/6328a070ddaab16faaf008cb9a8a6PatchThird Party Advisory
- https://github.com/adrienverge/openfortivpn/commit/cd9368c6a1b4ef91d77bb3fdbe2e5PatchThird Party Advisory
- https://github.com/adrienverge/openfortivpn/issues/536Issue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2020-7043?
CVE-2020-7043 is a vulnerability with a CVSS score of 9.1 (CRITICAL). An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstr...
How severe is CVE-2020-7043?
CVE-2020-7043 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-7043?
Check the references section above for vendor advisories and patch information. Affected products include: Openfortivpn Project Openfortivpn, Openssl Openssl, Fedoraproject Fedora, Opensuse Backports Sle, Opensuse Leap.