CVE-2020-7041 incorrect use of X509_check_host CVE-2020-7042 use of uninitialized memory in X509_check_host CVE-2020-7043 TLS Certificate CommonName NULL Byte Vulnerability Fixed in version 1.12 References: https://github.com/adrienverge/openfortivpn/issues/536 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7041 https://nvd.nist.gov/vuln/detail/CVE-2020-7041 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7042 https://nvd.nist.gov/vuln/detail/CVE-2020-7042 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7043 https://nvd.nist.gov/vuln/detail/CVE-2020-7043
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7e5ea44f7b0a08797db2da56e796498db09c55aa commit 7e5ea44f7b0a08797db2da56e796498db09c55aa Author: Johannes Huber <johu@gentoo.org> AuthorDate: 2020-03-28 08:28:03 +0000 Commit: Johannes Huber <johu@gentoo.org> CommitDate: 2020-03-28 08:28:03 +0000 net-vpn/openfortivpn: Version bump 1.13.2 Bug: https://bugs.gentoo.org/711018 Package-Manager: Portage-2.3.96, Repoman-2.3.22 Signed-off-by: Johannes Huber <johu@gentoo.org> net-vpn/openfortivpn/Manifest | 1 + net-vpn/openfortivpn/openfortivpn-1.13.2.ebuild | 38 +++++++++++++++++++++++++ 2 files changed, 39 insertions(+)
@maintainer(s), please advise if ready for stabilisation, or call yourself.
Please stabilize =net-vpn/openfortivpn-1.13.2. Thank you in advance
amd64 stable
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8432050432f615c45e1a07adab6accf701e57d1a commit 8432050432f615c45e1a07adab6accf701e57d1a Author: Johannes Huber <johu@gentoo.org> AuthorDate: 2020-03-31 09:32:37 +0000 Commit: Johannes Huber <johu@gentoo.org> CommitDate: 2020-03-31 09:32:37 +0000 net-vpn/openfortivpn: Security cleanup Remove vulnerable version 1.11.0 (CVE-2020-{7041,7042,7043}) Bug: https://bugs.gentoo.org/711018 Package-Manager: Portage-2.3.96, Repoman-2.3.22 Signed-off-by: Johannes Huber <johu@gentoo.org> net-vpn/openfortivpn/Manifest | 1 - net-vpn/openfortivpn/openfortivpn-1.11.0.ebuild | 38 ------------------------- 2 files changed, 39 deletions(-)
Thanks all.
GLSA Vote: No! Repository is clean, all done!