DescriptionAn issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a\ attack.
openfortivpn (PTS)buster1.8.1-1vulnerable
bookworm, sid1.19.0-2fixed

No version of openfortivpn was shipped with OpenSSL < 1.0.2, marking as unimportant

