PT-2015-6252 · Stunnel+2 · Stunnel+2

Johan Olofsson

+1

·

Published

2015-05-14

·

Updated

2024-06-15

·

CVE-2015-3644

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Stunnel versions 5.00 through 5.13
Description The issue allows remote attackers to bypass authentication due to a failure in redirecting client connections to the expected server after the initial connection when the redirect option is used.
Recommendations For versions 5.00 through 5.13, update to a version that contains a fix for this issue to prevent authentication bypass.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2391
CVE-2015-3644
DSA-3299-1
MGASA-2015-0289
OPENSUSE-SU-2024:12196-1
SUSE-SU-2015:1062-1
SUSE-SU-2015_1062-1

Affected Products

Alt Linux
Stunnel
Suse