PT-2015-6252 · Stunnel+2 · Stunnel+2
Johan Olofsson
+1
·
Published
2015-05-14
·
Updated
2024-06-15
·
CVE-2015-3644
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Stunnel versions 5.00 through 5.13
Description
The issue allows remote attackers to bypass authentication due to a failure in redirecting client connections to the expected server after the initial connection when the redirect option is used.
Recommendations
For versions 5.00 through 5.13, update to a version that contains a fix for this issue to prevent authentication bypass.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Stunnel
Suse