Cisco Anyconnect Opensuse



Conditions: Reportedly occurs using AnyConnect 4.0.x on RHEL 6, OpenSuSE 13.2, Fedora 22 and FreeBSD 10.0. Problem may occur on other distros as well. Problem may occur on other distros as well. Workarounds: Use OpenConnect, a free and open source SSL VPN client software initially created to support Cisco's AnyConnect SSL VPN. Pascal researched and found that the error, anyconnect was not able to establish a connection to the specified secure gateway is a known problem with Cisco clients before version 4, when these earlier clients are installed on Ubuntu 16.04+. The solution is either to downgrade your Ubuntu, or upgrade your Cisco client. NetworkManager-openconnect provides VPN support to NetworkManager for OpenConnect, an implementation of the Cisco AnyConnect VPN system. Version 1.2.6; Size 716 KB; openSUSE Leap 15.2; Direct Install Expert Download. Debian / OpenSUSE / Gentoo. The openconnect and NetworkManager-openconnect (or network-manager-openconnect) packages are included in most Linux distributions. The openconnect and network-manager-openconnect packages are included in Ubuntu but bug fixes are sometimes very slow. Citrix virtual apps chrome.

I decided to take the Cisco Anyconnect 3.1 client for a spin on 64-bit Suse 12.1
The issue I am seeing is that the client launches and when it attempts to run the Cisco Secure Destop (csd) binary it chokes. The reason why is interesting:
ldd shows /opt/cisco/anyconnect/bin/vpnui (32bit) links to all needed libraries, including libcurl.so in /opt/cisco/anyconnect/lib
So this launches fine.
In turn, it calls ~/.cisco/hostscan/bin/cscan (32bit) which logs:
/home/user/.cisco/hostscan/log/cscan.log
/var/log/messages
So the linker runs off to library land and comes back with /usr/lib64/libcurl.so.4, which of course is wrong ELF class.
My questions then are:
1) ldd shows cscan is not itself linked to any libcurl, but it tries to load /opt/cisco/anyconnect/lib/libcurl.so.3 - resulting in 'does not have the required support' (Cisco, you include a version of libcurl which does not work with your own product?) I'm curious why ldd does not show this:
2) I don't understand why the linker is linking to the 64bit lib when it is executing a 32bit binary. Tried to LD_PRELOAD the 32-bit one and LD_PRELOAD is not allowed. Does anyone have an idea on how to force it to find the (installed) 32bit version first?
This looks to be the same issue in: https://supportforums.cisco.com/thread/2145858 from April of this year - but no answers to that post.
Thanks for any tips on how to get this working.
OpenConnect is an SSL VPN client initially created to support Cisco's AnyConnect SSL VPN. It has since been extended to support the Pulse Connect Secure VPN (formerly known as Juniper Network Connect or Junos Pulse) and the Palo Alto Networks GlobalProtect SSL VPN.
A corresponding OpenConnect VPN server implementation can be found in the ocserv package.
Original maintainerMike Miller
Homepagehttp://www.infradead.org/openconnect.html
Fedora 31
OpenSUSE Tumbleweed
Fedora 30

Cisco Anyconnect Windows 10

Ubuntu 19.04
Ubuntu 20.04
Fedora 28
OpenSUSE Leap 15.0
OpenSUSE Leap 15.2
Ubuntu 17.10
Ubuntu 18.10
Ubuntu 16.04 LTS
DistributionVersionSincePackageInstalledPackager
Arch rolling extra/osxz1:8.05-12019-09-14589 kiB3.12 MiBLevente Polyak
Debian 10.0 buster/maindeb8.02-1+deb10u12020-02-08462 kiB2.51 MiBMike Miller
Debian 9.0 stretch/maindeb7.08-1+deb9u12020-02-08408 kiB2.23 MiBMike Miller
Fedora 28 releases/Everything-osrpm7.08-5.fc282019-01-14573 kiB2.38 MiBFedora Project
Fedora 28 releases/Workstation-osrpm7.08-5.fc282019-01-14573 kiB2.38 MiBFedora Project
Fedora 29 releases/Everything-osrpm7.08-8.fc292019-01-14564 kiB2.38 MiBFedora Project
Fedora 29 releases/Workstation-osrpm7.08-8.fc292019-01-14564 kiB2.38 MiBFedora Project
Fedora 29 releases-test/Everything-osrpm7.08-8.fc292019-01-14564 kiB2.38 MiBFedora Project
Fedora 29 releases-test/Workstation-osrpm7.08-8.fc292019-01-14564 kiB2.38 MiBFedora Project
Fedora 30 releases/Everything-osrpm8.02-3.fc302019-06-17508 kiB2.34 MiBFedora Project
Fedora 30 releases/Workstation-osrpm8.02-3.fc302019-06-17508 kiB2.34 MiBFedora Project
Fedora 30 releases-test/Workstation-osrpm8.02-3.fc302019-06-17508 kiB2.34 MiBFedora Project
Fedora 31 releases/Everything-osrpm8.05-1.fc312020-01-07684 kiB2.83 MiBFedora Project
Fedora rawhide development/Everything-osrpm8.05-2.fc322020-02-08684 kiB2.83 MiBFedora Project
Fedora rawhide development/Workstation-osrpm8.03-2.fc312019-08-03658 kiB2.77 MiBFedora Project
Manjaro rolling stable/extraxz1:8.02-12019-02-19559 kiB2.99 MiBLevente Polyak
Manjaro rolling testing/extraxz1:8.02-12019-02-14559 kiB2.99 MiBLevente Polyak
Manjaro rolling unstable/extraxz1:8.02-12019-02-12559 kiB2.99 MiBLevente Polyak
OpenSUSE Leap 15.0 ossrpm7.08-lp150.4.12019-01-17149 kiB324 kiBhttps://bugs.opensuse.org
OpenSUSE Leap 15.0 update/ossrpm7.08-lp150.5.3.12019-10-27137 kiB324 kiBhttp://bugs.opensuse.org
OpenSUSE Leap 15.1 ossrpm7.08-lp151.5.32019-01-23149 kiB324 kiBhttps://bugs.opensuse.org
OpenSUSE Leap 15.1 update/ossrpm7.08-lp151.6.3.12019-10-27137 kiB324 kiBhttp://bugs.opensuse.org
OpenSUSE Leap 15.2 ossrpm7.08-lp152.7.262020-03-23136 kiB324 kiBhttps://bugs.opensuse.org
OpenSUSE Leap 42.3 ossrpm7.06-5.22019-01-17120 kiB258 kiBhttp://bugs.opensuse.org
OpenSUSE Leap 42.3 update/ossrpm7.08-7.12019-01-21130 kiB283 kiBhttp://bugs.opensuse.org
OpenSUSE Tumbleweed ossrpm8.05-2.12020-01-1347.2 kiB101 kiBhttps://bugs.opensuse.org
Ubuntu 17.10 artful/universedeb7.08-12017-11-10382 kiB2.23 MiBUbuntu Developers
Ubuntu 18.04 LTS bionic/universedeb7.08-32018-03-07383 kiB2.23 MiBUbuntu Developers
Ubuntu 18.04 LTS bionic-updates/universedeb7.08-3ubuntu0.18.04.12019-06-17383 kiB2.23 MiBUbuntu Developers
Ubuntu 18.10 cosmic/universedeb7.08-32019-01-14383 kiB2.23 MiBUbuntu Developers
Ubuntu 19.04 disco/universedeb8.02-12019-01-28434 kiB2.51 MiBUbuntu Developers
Ubuntu 19.10 eoan/universedeb8.02-1build12019-09-06434 kiB2.52 MiBUbuntu Developers
Ubuntu 20.04 focal/universedeb8.02-1build12020-01-07434 kiB2.52 MiBUbuntu Developers
Ubuntu 16.04 LTS xenial/universedeb7.06-2build22017-11-10300 kiB1.59 MiBUbuntu Developers

openconnect(8)

openconnect - Multi-protocol VPN client, for Cisco AnyConnect VPNs and others

OpenSUSE Leap 15.2 oss: Updated from 7.08-lp152.7.24 to 7.08-lp152.7.26

  • Add openconnect-CVE-2019-16239.patch: Fix buffer overflow with chunked HTTP handling(bsc#1151178, CVE-2019-16239).

OpenSUSE Leap 15.2 oss: Updated from 7.08-lp152.7.20 to 7.08-lp152.7.24

  • Add openconnect-CVE-2019-16239.patch: Fix buffer overflow with chunked HTTP handling(bsc#1151178, CVE-2019-16239).

OpenSUSE Leap 15.2 oss: Updated from 7.08-lp152.7.19 to 7.08-lp152.7.20

  • Add openconnect-CVE-2019-16239.patch: Fix buffer overflow with chunked HTTP handling(bsc#1151178, CVE-2019-16239).

OpenSUSE Leap 15.2 oss: Updated from 7.08-lp152.7.18 to 7.08-lp152.7.19

  • Add openconnect-CVE-2019-16239.patch: Fix buffer overflow with chunked HTTP handling(bsc#1151178, CVE-2019-16239).
Install

OpenSUSE Leap 15.2 oss: Updated from 7.08-lp152.7.15 to 7.08-lp152.7.18

  • Add openconnect-CVE-2019-16239.patch: Fix buffer overflow with chunked HTTP handling(bsc#1151178, CVE-2019-16239).

Fedora rawhide development/Everything-os: Updated from 8.05-1.fc32 to 8.05-2.fc32

Debian 10.0 buster-proposed-updates/main: Version 8.02-1+deb10u1 removed

Debian 10.0 buster/main: Updated from 8.02-1 to 8.02-1+deb10u1

  • Non-maintainer upload by the Security Team.
  • Close HTTPS connection on failure returns from process_http_response()
  • Fix buffer overflow with chunked HTTP handling (CVE-2019-16239) (Closes: #940871)

Debian 9.0 stretch-proposed-updates/main: Version 7.08-1+deb9u1 removed

Debian 9.0 stretch/main: Updated from 7.08-1 to 7.08-1+deb9u1

  • Non-maintainer upload by the Security Team.
  • Close HTTPS connection on failure returns from process_http_response()
  • Fix buffer overflow with chunked HTTP handling (CVE-2019-16239) (Closes: #940871)

OpenSUSE Leap 15.2 oss: Updated from 7.08-lp152.7.13 to 7.08-lp152.7.15

  • Add openconnect-CVE-2019-16239.patch: Fix buffer overflow with chunked HTTP handling(bsc#1151178, CVE-2019-16239).

Debian 10.0 buster-proposed-updates/main: Version 8.02-1+deb10u1 introduced

  • Non-maintainer upload by the Security Team.
  • Close HTTPS connection on failure returns from process_http_response()
  • Fix buffer overflow with chunked HTTP handling (CVE-2019-16239) (Closes: #940871)

Debian 9.0 stretch-proposed-updates/main: Version 7.08-1+deb9u1 introduced

  • Non-maintainer upload by the Security Team.
  • Close HTTPS connection on failure returns from process_http_response()
  • Fix buffer overflow with chunked HTTP handling (CVE-2019-16239) (Closes: #940871)

OpenSUSE Leap 15.2 oss: Updated from 7.08-lp152.7.12 to 7.08-lp152.7.13

Cisco Anyconnect Linux Client

  • Add openconnect-CVE-2019-16239.patch: Fix buffer overflow with chunked HTTP handling(bsc#1151178, CVE-2019-16239).

OpenSUSE Tumbleweed oss: Updated from 8.05-1.1 to 8.05-2.1

  • Remove tncc-wrapper.py script as it is python2 only bsc#1157446

Fedora 31 releases/Everything-os: Version 8.05-1.fc31 introduced

  • Update to 8.05 release (CVE-2019-16239)

OpenSUSE Leap 15.2 oss: Version 7.08-lp152.7.12 introduced

  • Add openconnect-CVE-2019-16239.patch: Fix buffer overflow with chunked HTTP handling(bsc#1151178, CVE-2019-16239).

Ubuntu 20.04 focal/universe: Version 8.02-1build1 introduced

OpenSUSE Tumbleweed oss: Updated from 8.03-1.4 to 8.05-1.1

  • No need to ship hipreport-android.sh as it is intented for android systems only

Where Is Cisco Anyconnect Installed On Ubuntu

OpenSUSE Leap 15.0 update/oss: Version 7.08-lp150.5.3.1 introduced

  • Add openconnect-CVE-2019-16239.patch: Fix buffer overflow with chunked HTTP handling(bsc#1151178, CVE-2019-16239).
openconnect-dbg - debugging symbols for the OpenConnect VPN client
openconnect-debuginfo - Debug information for package openconnect
Cisco Anyconnect Opensuse
openconnect-debugsource - Debug sources for package openconnect

Cisco Anyconnect Vpn Client Download

openconnect-devel - Development package for OpenConnect VPN authentication tools

Cisco Anyconnect Vpn Linux

openconnect-lang - Translations for package openconnect