Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27518
HistoryOct 04, 2020 - 4:42 a.m.

Arbitrary Code Execution

2020-10-0404:42:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
openconnect
arbitrary code execution
buffer overflow
process_http_response
http chunked encoding
malicious server

EPSS

0.008

Percentile

81.8%

openconnect is vulnerable to arbitrary code execution. A buffer overflow vulnerability occurs in the process_http_response when a malicious server uses HTTP chunked encoding with malicious chunk sizes, resulting in arbitrary code execution.