|
|
| |
|
| |
stunnel: code execution
| Package(s): | stunnel |
CVE #(s): | CVE-2013-1762
|
| Created: | March 18, 2013 |
Updated: | March 20, 2013 |
| Description: |
From the Mageia advisory:
stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM
authentication are enabled, does not correctly perform integer conversion,
which allows remote proxy servers to execute arbitrary code via a
crafted request that triggers a buffer overflow. |
| Alerts: |
|
( Log in to post comments)
|
|
|