PT-2022-36627 · Stunnel+1 · Stunnel+1
Published
2022-03-16
·
Updated
2022-03-16
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
stunnel versions prior to 5.62
Description
The issue concerns security bugfixes, including a fix for the 'redirect' option to properly handle unauthenticated requests and a fix for a double free with OpenSSL older than 1.1.0. Additionally, hardening was added to the systemd service.
Recommendations
For stunnel versions prior to 5.62, update to version 5.62 to resolve the issue. As a temporary workaround, consider disabling the
redirect option until a patch is available. Restrict access to the stunnel service to minimize the risk of exploitation. Avoid using the protocol option in combination with redirect for 'smtp', 'pop3', and 'imap' protocols until the issue is resolved. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssl
Stunnel