Oval Definition:oval:org.mitre.oval:def:20019
Revision Date:2014-06-23Version:5
Title:DSA-2664-1 stunnel4 - buffer overflow
Description:Stunnel, a program designed to work as an universal SSL tunnel for network daemons, is prone to a buffer overflow vulnerability when using the Microsoft NT LAN Manager (NTLM) authentication (protocolAuthentication = NTLM) together with the connect protocol method (protocol = connect). With these prerequisites and using stunnel4 in SSL client mode (client = yes) on a 64 bit host, an attacker could possibly execute arbitrary code with the privileges of the stunnel process, if the attacker can either control the specified proxy server or perform man-in-the-middle attacks on the tcp session between stunnel and the proxy sever.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2013-1762
DSA-2664-1
Platform(s):Debian GNU/kFreeBSD 6.0
Debian GNU/Linux 6.0
Product(s):stunnel4
Definition Synopsis
  • Debian 6.0 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND stunnel4 DPKG is earlier than 3:4.29-1+squeeze1
  • BACK