OpenConnect: User-assisted execution of arbitrary code A buffer overflow in OpenConnect could result in execution of arbitrary code or Denial of Service. openconnect 2014-05-18 2014-05-18 457068 remote 4.08 4.08

OpenConnect is a free client for Cisco AnyConnect SSL VPN software.

A stack-based buffer overflow error has been discovered in OpenConnect.

A remote attacker could entice a user to connect to a malicious VPN server, possibly resulting in execution of arbitrary code with the privileges of the process, or a Denial of Service condition.

There is no known workaround at this time.

All OpenConnect users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/openconnect-4.08"
CVE-2012-6128 ackle ackle