LWN.net Logo

stunnel: code execution

Package(s):stunnel CVE #(s):CVE-2013-1762
Created:March 18, 2013 Updated:March 20, 2013
Description: From the Mageia advisory:

stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.

Alerts:
Mageia MGASA-2013-0097 2013-03-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds