PT-2003-1067 · Stunnel · Stunnel
Steve Grubb
·
Published
2003-09-04
·
Updated
2016-10-18
·
CVE-2003-0740
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Stunnel versions 4.00 and 3.24 and earlier
Description
The issue allows local users to hijack the Stunnel server due to a leaked privileged file descriptor returned by listen(). Multiple vulnerabilities in the stunnel package may lead to disruption of confidentiality, integrity, and availability of protected information, and exploitation can be done locally.
Recommendations
For Stunnel versions 4.00 and 3.24 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Stunnel