Search

published date: October 20, 2003

CVE-2003-0740 : Stunnel 4.00, and 3.24...

Description

Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.

Product(s):

  • Stunnel 3.10
  • Stunnel 3.11
  • Stunnel 3.12
  • Stunnel 3.13
  • Stunnel 3.14
  • Stunnel 3.15

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2003-0740, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2003-0740 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?