{"id":"SUSE-SU-2024:0317-1","summary":"Security update for openconnect","details":"This update for openconnect fixes the following issues:\n\n- Update to release 9.12:\n\n  * Explicitly reject overly long tun device names.\n  * Increase maximum input size from stdin (#579).\n  * Ignore 0.0.0.0 as NBNS address (!446, vpnc-scripts#58).\n  * Fix stray (null) in URL path after Pulse authentication (4023bd95).\n  * Fix config XML parsing mistake that left GlobalProtect ESP non-working in v9.10 (!475).\n  * Fix case sensitivity in GPST header matching (!474).\n\n- Update to release 9.10:\n\n  * Fix external browser authentication with KDE plasma-nm \u003c 5.26.\n  * Always redirect stdout to stderr when spawning external browser.\n  * Increase default queue length to 32 packets.\n  * Fix receiving multiple packets in one TLS frame, and single packets split across multiple TLS frames, for Array.\n  * Handle idiosyncratic variation in search domain separators for all protocols\n  * Support region selection field for Pulse authentication \n  * Support modified configuration packet from Pulse 9.1R16 servers \n  * Allow hidden form fields to be populated or converted to text fields on the command line\n  * Support yet another strange way of encoding challenge-based 2FA for GlobalProtect\n  * Add --sni option (and corresponding C and Java API functions) to allow domain-fronting connections in censored/filtered network environments\n  * Parrot a GlobalProtect server's software version, if present, as the client version (!333)\n  * Fix NULL pointer dereference that has left Android builds broken since v8.20 (!389).\n  * Fix Fortinet authentication bug where repeated SVPNCOOKIE causes segfaults (#514, !418).\n  * Support F5 VPNs which encode authentication forms only in JSON, not in HTML.\n  * Support simultaneous IPv6 and Legacy IP ('dual-stack') for Fortinet .\n  * Support 'FTM-push' token mode for Fortinet VPNs .\n  * Send IPv6-compatible version string in Pulse IF/T session establishment\n  * Add --no-external-auth option to not advertise external-browser authentication\n  * Many small improvements in server response parsing, and better logging messages and documentation.\n\n- Update to release 9.01:\n\n  * Add support for AnyConnect 'Session Token Re-use Anchor Protocol' (STRAP) \n  * Add support for AnyConnect 'external browser' SSO mode\n  * Bugfix RSA SecurID token decryption and PIN entry forms, broken in v8.20\n  * Support Cisco's multiple-certificate authentication\n  * Revert GlobalProtect default route handling change from v8.20\n  * Suppo split-exclude routes for Fortinet\n  * Add webview callback and SAML/SSO support for AnyConnect, GlobalProtect\n\n- Update to release 8.20:\n\n  * Support non-AEAD ciphersuites in DTLSv1.2 with AnyConnect.\n  * Emulated a newer version of GlobalProtect official clients,\n    5.1.5-8; was 4.0.2-19\n  * Support Juniper login forms containing both password and 2FA\n    token\n  * Explicitly disable 3DES and RC4, unless enabled with\n    --allow-insecure-crypto\n  * Allow protocols to delay tunnel setup and shutdown (!117)\n  * Support for GlobalProtect IPv6\n  * SIGUSR1now causes OpenConnect to log detailed connection\n    information and statistics\n  * Allow --servercert to be specified multiple times in order to\n    accept server certificates matching more than one possible\n    fingerprint\n  * Demangle default routes sent as split routes by GlobalProtect\n  * Support more Juniper login forms, including some SSO forms\n  * Restore compatibility with newer Cisco servers, by no longer\n    sending them the X-AnyConnect-Platform header\n  * Add support for PPP-based protocols, currently over TLS only.\n  * Add support for two PPP-based protocols, F5 with\n    --protocol=f5 and Fortinet with --protocol=fortinet.\n  * Add support for Array Networks SSL VPN.\n  * Support TLSv1.3 with TPMv2 EC and RSA keys, add test cases\n    for swtpm and hardware TPM.\n\n- Import the latest version of the vpnc-script (bsc#1140772)\n\n  * This brings a lot of improvements for non-trivial network setups, IPv6 etc\n\n- Build with --without-gnutls-version-check\n\n- Update to version 8.10:\n\n  * Install bash completion script to\n    ${datadir}/bash-completion/completions/openconnect.\n  * Improve compatibility of csd-post.sh trojan.\n  * Fix potential buffer overflow with GnuTLS describing local\n    certs (CVE-2020-12823, bsc#1171862,\n    gl#openconnect/openconnect!108).\n\n- Introduce subpackage for bash-completion\n\n- Update to 8.09:\n\n  * Add bash completion support.\n  * Give more helpful error in case of Pulse servers asking for\n    TNCC.\n  * Sanitize non-canonical Legacy IP network addresses.\n  * Fix OpenSSL validation for trusted but invalid certificates\n    (CVE-2020-12105 bsc#1170452).\n  * Convert tncc-wrapper.py to Python 3, and include modernized\n    tncc-emulate.py as well. (!91)\n  * Disable Nagle's algorithm for TLS sockets, to improve\n    interactivity when tunnel runs over TCP rather than UDP.\n  * GlobalProtect: more resilient handling of periodic HIP check\n    and login arguments, and predictable naming of challenge forms.\n  * Work around PKCS#11 tokens which forget to set\n    CKF_LOGIN_REQUIRED.\n\n- Update to 8.0.8:\n\n  * Fix check of pin-sha256: public key hashes to be case sensitive\n  * Don't give non-functioning stderr to CSD trojan scripts.\n  * Fix crash with uninitialised OIDC token.\n\n- Update to 8.0.7:\n\n  * Don't abort Pulse connection when server-provided certificate\n    MD5 doesn't match.\n  * Fix off-by-one in check for bad GnuTLS versions, and add build\n    and run time checks.\n  * Don't abort connection if CSD wrapper script returns non-zero\n    (for now).\n  * Make --passtos work for protocols that use ESP, in addition\n    to DTLS.\n  * Convert tncc-wrapper.py to Python 3, and include modernized\n    tncc-emulate.py as well.\n\n- Remove tncc-wrapper.py script as it is python2 only bsc#1157446\n\n- No need to ship hipreport-android.sh as it is intented for\n  android systems only\n\n- Update to 8.0.5:\n\n  * Minor fixes to build on specific platforms\n  * Includes fix for a buffer overflow with chunked HTTP handling\n    (CVE-2019-16239, bsc#1151178) \n\n- Use python3 to generate the web data as now it is supported\n  by upstream\n\n- Update to 8.0.3:\n\n  * Fix Cisco DTLSv1.2 support for AES256-GCM-SHA384.\n  * Fix recognition of OTP password fields.\n\n- Update to 8.02:\n\n  * Fix GNU/Hurd build.\n  * Discover vpnc-script in default packaged location on FreeBSD/OpenBSD.\n  * Support split-exclude routes for GlobalProtect.\n  * Fix GnuTLS builds without libtasn1.\n  * Fix DTLS support with OpenSSL 1.1.1+.\n  * Add Cisco-compatible DTLSv1.2 support.\n  * Invoke script with reason=attempt-reconnect before doing so.\n \n\n- Update to 8.01:\n\n  * Clear form submissions (which may include passwords) before\n    freeing (CVE-2018-20319, bsc#1215669).\n  * Allow form responses to be provided on command line.\n  * Add support for SSL keys stored in TPM2.\n  * Fix ESP rekey when replay protection is disabled.\n  * Drop support for GnuTLS older than 3.2.10.\n  * Fix --passwd-on-stdin for Windows to not forcibly open console.\n  * Fix portability of shell scripts in test suite.\n  * Add Google Authenticator TOTP support for Juniper.\n  * Add RFC7469 key PIN support for cert hashes.\n  * Add protocol method to securely log out the Juniper session.\n  * Relax requirements for Juniper hostname packet response to support old gateways.\n  * Add API functions to query the supported protocols.\n  * Verify ESP sequence numbers and warn even if replay protection is disabled.\n  * Add support for PAN GlobalProtect VPN protocol (--protocol=gp).\n  * Reorganize listing of command-line options, and include information on supported protocols.\n  * SIGTERM cleans up the session similarly to SIGINT.\n  * Fix memset_s() arguments.\n  * Fix OpenBSD build.\n\n- Explicitely enable all the features as needed to stop build if\n  something is missing\n","modified":"2026-02-04T03:43:17.365277Z","published":"2024-02-02T09:35:06Z","related":["CVE-2018-20319","CVE-2020-12105","CVE-2020-12823"],"upstream":["CVE-2018-20319","CVE-2020-12105","CVE-2020-12823"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20240317-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1140772"},{"type":"REPORT","url":"https://bugzilla.suse.com/1157446"},{"type":"REPORT","url":"https://bugzilla.suse.com/1170452"},{"type":"REPORT","url":"https://bugzilla.suse.com/1171862"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215669"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20319"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-12105"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-12823"}],"affected":[{"package":{"name":"oath-toolkit","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP5","purl":"pkg:rpm/suse/oath-toolkit&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.2-150000.3.5.1"}]}],"ecosystem_specific":{"binaries":[{"liboath-devel":"2.6.2-150000.3.5.1","liboath0":"2.6.2-150000.3.5.1","oath-toolkit-xml":"2.6.2-150000.3.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0317-1.json"}},{"package":{"name":"oath-toolkit","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP5","purl":"pkg:rpm/suse/oath-toolkit&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.2-150000.3.5.1"}]}],"ecosystem_specific":{"binaries":[{"libpskc0":"2.6.2-150000.3.5.1","oath-toolkit":"2.6.2-150000.3.5.1","openconnect-devel":"9.12-150400.15.3.1","openconnect-lang":"9.12-150400.15.3.1","openconnect":"9.12-150400.15.3.1","libpskc-devel":"2.6.2-150000.3.5.1","libstoken1":"0.81-150400.13.2.1","openconnect-doc":"9.12-150400.15.3.1","stoken-devel":"0.81-150400.13.2.1","stoken-gui":"0.81-150400.13.2.1","stoken":"0.81-150400.13.2.1","libopenconnect5":"9.12-150400.15.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0317-1.json"}},{"package":{"name":"openconnect","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP5","purl":"pkg:rpm/suse/openconnect&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.12-150400.15.3.1"}]}],"ecosystem_specific":{"binaries":[{"libopenconnect5":"9.12-150400.15.3.1","libstoken1":"0.81-150400.13.2.1","openconnect-devel":"9.12-150400.15.3.1","openconnect":"9.12-150400.15.3.1","stoken":"0.81-150400.13.2.1","libpskc-devel":"2.6.2-150000.3.5.1","libpskc0":"2.6.2-150000.3.5.1","oath-toolkit":"2.6.2-150000.3.5.1","openconnect-doc":"9.12-150400.15.3.1","openconnect-lang":"9.12-150400.15.3.1","stoken-devel":"0.81-150400.13.2.1","stoken-gui":"0.81-150400.13.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0317-1.json"}},{"package":{"name":"stoken","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP5","purl":"pkg:rpm/suse/stoken&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.81-150400.13.2.1"}]}],"ecosystem_specific":{"binaries":[{"openconnect-doc":"9.12-150400.15.3.1","openconnect":"9.12-150400.15.3.1","stoken-devel":"0.81-150400.13.2.1","stoken-gui":"0.81-150400.13.2.1","libpskc-devel":"2.6.2-150000.3.5.1","libpskc0":"2.6.2-150000.3.5.1","openconnect-devel":"9.12-150400.15.3.1","openconnect-lang":"9.12-150400.15.3.1","stoken":"0.81-150400.13.2.1","libopenconnect5":"9.12-150400.15.3.1","libstoken1":"0.81-150400.13.2.1","oath-toolkit":"2.6.2-150000.3.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0317-1.json"}},{"package":{"name":"oath-toolkit","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP5","purl":"pkg:rpm/suse/oath-toolkit&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.2-150000.3.5.1"}]}],"ecosystem_specific":{"binaries":[{"libpskc0":"2.6.2-150000.3.5.1","libstoken1":"0.81-150400.13.2.1","openconnect-devel":"9.12-150400.15.3.1","openconnect-lang":"9.12-150400.15.3.1","openconnect":"9.12-150400.15.3.1","stoken-devel":"0.81-150400.13.2.1","libopenconnect5":"9.12-150400.15.3.1","libpskc-devel":"2.6.2-150000.3.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0317-1.json"}},{"package":{"name":"openconnect","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP5","purl":"pkg:rpm/suse/openconnect&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.12-150400.15.3.1"}]}],"ecosystem_specific":{"binaries":[{"openconnect-devel":"9.12-150400.15.3.1","openconnect-lang":"9.12-150400.15.3.1","openconnect":"9.12-150400.15.3.1","stoken-devel":"0.81-150400.13.2.1","libopenconnect5":"9.12-150400.15.3.1","libpskc-devel":"2.6.2-150000.3.5.1","libpskc0":"2.6.2-150000.3.5.1","libstoken1":"0.81-150400.13.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0317-1.json"}},{"package":{"name":"stoken","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP5","purl":"pkg:rpm/suse/stoken&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.81-150400.13.2.1"}]}],"ecosystem_specific":{"binaries":[{"openconnect-devel":"9.12-150400.15.3.1","openconnect-lang":"9.12-150400.15.3.1","openconnect":"9.12-150400.15.3.1","stoken-devel":"0.81-150400.13.2.1","libopenconnect5":"9.12-150400.15.3.1","libpskc-devel":"2.6.2-150000.3.5.1","libpskc0":"2.6.2-150000.3.5.1","libstoken1":"0.81-150400.13.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0317-1.json"}},{"package":{"name":"oath-toolkit","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/oath-toolkit&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.2-150000.3.5.1"}]}],"ecosystem_specific":{"binaries":[{"liboath-devel":"2.6.2-150000.3.5.1","openconnect-devel":"9.12-150400.15.3.1","openconnect-doc":"9.12-150400.15.3.1","libpskc0":"2.6.2-150000.3.5.1","libstoken1":"0.81-150400.13.2.1","oath-toolkit":"2.6.2-150000.3.5.1","stoken-devel":"0.81-150400.13.2.1","stoken-gui":"0.81-150400.13.2.1","stoken":"0.81-150400.13.2.1","liboath0":"2.6.2-150000.3.5.1","oath-toolkit-xml":"2.6.2-150000.3.5.1","openconnect-lang":"9.12-150400.15.3.1","pam_oath":"2.6.2-150000.3.5.1","libopenconnect5":"9.12-150400.15.3.1","libpskc-devel":"2.6.2-150000.3.5.1","openconnect":"9.12-150400.15.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0317-1.json"}},{"package":{"name":"openconnect","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/openconnect&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.12-150400.15.3.1"}]}],"ecosystem_specific":{"binaries":[{"openconnect":"9.12-150400.15.3.1","oath-toolkit-xml":"2.6.2-150000.3.5.1","openconnect-devel":"9.12-150400.15.3.1","oath-toolkit":"2.6.2-150000.3.5.1","pam_oath":"2.6.2-150000.3.5.1","stoken-gui":"0.81-150400.13.2.1","stoken":"0.81-150400.13.2.1","liboath-devel":"2.6.2-150000.3.5.1","libopenconnect5":"9.12-150400.15.3.1","libpskc-devel":"2.6.2-150000.3.5.1","libpskc0":"2.6.2-150000.3.5.1","libstoken1":"0.81-150400.13.2.1","openconnect-doc":"9.12-150400.15.3.1","liboath0":"2.6.2-150000.3.5.1","openconnect-lang":"9.12-150400.15.3.1","stoken-devel":"0.81-150400.13.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0317-1.json"}},{"package":{"name":"stoken","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/stoken&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.81-150400.13.2.1"}]}],"ecosystem_specific":{"binaries":[{"openconnect-devel":"9.12-150400.15.3.1","openconnect":"9.12-150400.15.3.1","liboath-devel":"2.6.2-150000.3.5.1","liboath0":"2.6.2-150000.3.5.1","oath-toolkit-xml":"2.6.2-150000.3.5.1","oath-toolkit":"2.6.2-150000.3.5.1","openconnect-doc":"9.12-150400.15.3.1","stoken-devel":"0.81-150400.13.2.1","libopenconnect5":"9.12-150400.15.3.1","libpskc-devel":"2.6.2-150000.3.5.1","libpskc0":"2.6.2-150000.3.5.1","libstoken1":"0.81-150400.13.2.1","stoken-gui":"0.81-150400.13.2.1","stoken":"0.81-150400.13.2.1","openconnect-lang":"9.12-150400.15.3.1","pam_oath":"2.6.2-150000.3.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0317-1.json"}}],"schema_version":"1.7.3"}