Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2019-16239
process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.048
EPSS Ranking
89.1%
CVSS Severity
CVSS v3 Score
9.8
CVSS v2 Score
7.5
References
http://lists.infradead.org/pipermail/openconnect-devel/2019-September/005412.html
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00060.html
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00061.html
https://lists.debian.org/debian-lts-announce/2019/10/msg00003.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FX56KYWC7X4ETV4P6HGJC7GZUEBITBBS/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HDMZGNBLZZKAGBI2PNXYWWKLD2LXKFH6/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WI7ZENFAWCHF2RU4NHPL2CU4WGZ4BNDJ/
https://seclists.org/bugtraq/2020/Jan/31
https://t2.fi/schedule/2019/
https://usn.ubuntu.com/4565-1/
https://www.debian.org/security/2020/dsa-4607
http://lists.infradead.org/pipermail/openconnect-devel/2019-September/005412.html
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00060.html
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00061.html
https://lists.debian.org/debian-lts-announce/2019/10/msg00003.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FX56KYWC7X4ETV4P6HGJC7GZUEBITBBS/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HDMZGNBLZZKAGBI2PNXYWWKLD2LXKFH6/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WI7ZENFAWCHF2RU4NHPL2CU4WGZ4BNDJ/
https://seclists.org/bugtraq/2020/Jan/31
https://t2.fi/schedule/2019/
https://usn.ubuntu.com/4565-1/
https://www.debian.org/security/2020/dsa-4607
Products affected by CVE-2019-16239
Infradead
»
Openconnect
»
Version:
1.00
cpe:2.3:a:infradead:openconnect:1.00
Infradead
»
Openconnect
»
Version:
1.10
cpe:2.3:a:infradead:openconnect:1.10
Infradead
»
Openconnect
»
Version:
1.20
cpe:2.3:a:infradead:openconnect:1.20
Infradead
»
Openconnect
»
Version:
1.30
cpe:2.3:a:infradead:openconnect:1.30
Infradead
»
Openconnect
»
Version:
1.40
cpe:2.3:a:infradead:openconnect:1.40
Infradead
»
Openconnect
»
Version:
2.00
cpe:2.3:a:infradead:openconnect:2.00
Infradead
»
Openconnect
»
Version:
2.01
cpe:2.3:a:infradead:openconnect:2.01
Infradead
»
Openconnect
»
Version:
2.10
cpe:2.3:a:infradead:openconnect:2.10
Infradead
»
Openconnect
»
Version:
2.11
cpe:2.3:a:infradead:openconnect:2.11
Infradead
»
Openconnect
»
Version:
2.12
cpe:2.3:a:infradead:openconnect:2.12
Infradead
»
Openconnect
»
Version:
2.20
cpe:2.3:a:infradead:openconnect:2.20
Infradead
»
Openconnect
»
Version:
2.21
cpe:2.3:a:infradead:openconnect:2.21
Infradead
»
Openconnect
»
Version:
2.22
cpe:2.3:a:infradead:openconnect:2.22
Infradead
»
Openconnect
»
Version:
2.23
cpe:2.3:a:infradead:openconnect:2.23
Infradead
»
Openconnect
»
Version:
2.24
cpe:2.3:a:infradead:openconnect:2.24
Infradead
»
Openconnect
»
Version:
2.25
cpe:2.3:a:infradead:openconnect:2.25
Infradead
»
Openconnect
»
Version:
2.26
cpe:2.3:a:infradead:openconnect:2.26
Infradead
»
Openconnect
»
Version:
3.00
cpe:2.3:a:infradead:openconnect:3.00
Infradead
»
Openconnect
»
Version:
3.01
cpe:2.3:a:infradead:openconnect:3.01
Infradead
»
Openconnect
»
Version:
3.02
cpe:2.3:a:infradead:openconnect:3.02
Infradead
»
Openconnect
»
Version:
3.11
cpe:2.3:a:infradead:openconnect:3.11
Infradead
»
Openconnect
»
Version:
3.12
cpe:2.3:a:infradead:openconnect:3.12
Infradead
»
Openconnect
»
Version:
3.13
cpe:2.3:a:infradead:openconnect:3.13
Infradead
»
Openconnect
»
Version:
3.14
cpe:2.3:a:infradead:openconnect:3.14
Infradead
»
Openconnect
»
Version:
3.15
cpe:2.3:a:infradead:openconnect:3.15
Infradead
»
Openconnect
»
Version:
3.16
cpe:2.3:a:infradead:openconnect:3.16
Infradead
»
Openconnect
»
Version:
3.17
cpe:2.3:a:infradead:openconnect:3.17
Infradead
»
Openconnect
»
Version:
3.18
cpe:2.3:a:infradead:openconnect:3.18
Infradead
»
Openconnect
»
Version:
3.19
cpe:2.3:a:infradead:openconnect:3.19
Infradead
»
Openconnect
»
Version:
3.20
cpe:2.3:a:infradead:openconnect:3.20
Infradead
»
Openconnect
»
Version:
3.99
cpe:2.3:a:infradead:openconnect:3.99
Infradead
»
Openconnect
»
Version:
4.00
cpe:2.3:a:infradead:openconnect:4.00
Infradead
»
Openconnect
»
Version:
4.01
cpe:2.3:a:infradead:openconnect:4.01
Infradead
»
Openconnect
»
Version:
4.02
cpe:2.3:a:infradead:openconnect:4.02
Infradead
»
Openconnect
»
Version:
4.03
cpe:2.3:a:infradead:openconnect:4.03
Infradead
»
Openconnect
»
Version:
4.04
cpe:2.3:a:infradead:openconnect:4.04
Infradead
»
Openconnect
»
Version:
4.05
cpe:2.3:a:infradead:openconnect:4.05
Infradead
»
Openconnect
»
Version:
4.06
cpe:2.3:a:infradead:openconnect:4.06
Infradead
»
Openconnect
»
Version:
4.07
cpe:2.3:a:infradead:openconnect:4.07
Infradead
»
Openconnect
»
Version:
4.08
cpe:2.3:a:infradead:openconnect:4.08
Infradead
»
Openconnect
»
Version:
4.99
cpe:2.3:a:infradead:openconnect:4.99
Infradead
»
Openconnect
»
Version:
5.00
cpe:2.3:a:infradead:openconnect:5.00
Infradead
»
Openconnect
»
Version:
5.01
cpe:2.3:a:infradead:openconnect:5.01
Infradead
»
Openconnect
»
Version:
5.02
cpe:2.3:a:infradead:openconnect:5.02
Infradead
»
Openconnect
»
Version:
5.03
cpe:2.3:a:infradead:openconnect:5.03
Infradead
»
Openconnect
»
Version:
5.99
cpe:2.3:a:infradead:openconnect:5.99
Infradead
»
Openconnect
»
Version:
6.00
cpe:2.3:a:infradead:openconnect:6.00
Infradead
»
Openconnect
»
Version:
7.00
cpe:2.3:a:infradead:openconnect:7.00
Infradead
»
Openconnect
»
Version:
7.01
cpe:2.3:a:infradead:openconnect:7.01
Infradead
»
Openconnect
»
Version:
7.02
cpe:2.3:a:infradead:openconnect:7.02
Infradead
»
Openconnect
»
Version:
7.03
cpe:2.3:a:infradead:openconnect:7.03
Infradead
»
Openconnect
»
Version:
7.04
cpe:2.3:a:infradead:openconnect:7.04
Infradead
»
Openconnect
»
Version:
7.05
cpe:2.3:a:infradead:openconnect:7.05
Infradead
»
Openconnect
»
Version:
7.06
cpe:2.3:a:infradead:openconnect:7.06
Infradead
»
Openconnect
»
Version:
7.07
cpe:2.3:a:infradead:openconnect:7.07
Infradead
»
Openconnect
»
Version:
7.08
cpe:2.3:a:infradead:openconnect:7.08
Infradead
»
Openconnect
»
Version:
8.00
cpe:2.3:a:infradead:openconnect:8.00
Infradead
»
Openconnect
»
Version:
8.01
cpe:2.3:a:infradead:openconnect:8.01
Infradead
»
Openconnect
»
Version:
8.02
cpe:2.3:a:infradead:openconnect:8.02
Infradead
»
Openconnect
»
Version:
8.03
cpe:2.3:a:infradead:openconnect:8.03
Infradead
»
Openconnect
»
Version:
8.04
cpe:2.3:a:infradead:openconnect:8.04
Canonical
»
Ubuntu Linux
»
Version:
18.04
cpe:2.3:o:canonical:ubuntu_linux:18.04
Debian
»
Debian Linux
»
Version:
10.0
cpe:2.3:o:debian:debian_linux:10.0
Debian
»
Debian Linux
»
Version:
8.0
cpe:2.3:o:debian:debian_linux:8.0
Debian
»
Debian Linux
»
Version:
9.0
cpe:2.3:o:debian:debian_linux:9.0
Fedoraproject
»
Fedora
»
Version:
29
cpe:2.3:o:fedoraproject:fedora:29
Fedoraproject
»
Fedora
»
Version:
30
cpe:2.3:o:fedoraproject:fedora:30
Fedoraproject
»
Fedora
»
Version:
31
cpe:2.3:o:fedoraproject:fedora:31
Opensuse
»
Leap
»
Version:
15.0
cpe:2.3:o:opensuse:leap:15.0
Opensuse
»
Leap
»
Version:
15.1
cpe:2.3:o:opensuse:leap:15.1
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved