OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.
https://security.gentoo.org/glsa/202006-15
https://lists.debian.org/debian-lts-announce/2020/05/msg00015.html
https://gitlab.com/openconnect/openconnect/-/merge_requests/108
https://bugs.gentoo.org/721570
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00056.html
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00039.html