CVE-2012-6128: Infradead Openconnect
Medium severity, CVSS 5.0. EPSS: 2.6% chance of exploitation in the next 30 days.
Multiple stack-based buffer overflows in http.c in OpenConnect before 4.08 allow remote VPN gateways to cause a denial of service (application crash) via a long (1) hostname, (2) path, or (3) cookie list in a response.
Affected products
- Infradead Openconnect: up to and including 4.07; version 1.00 only; version 1.10 only; version 1.20 only; version 1.30 only; version 1.40 only; …
Published 2013-02-24. Last modified 2026-06-16.