CVE-2013-1762

stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:stunnel:stunnel:*:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.21:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.22:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.23:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.24:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.25:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.26:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.27:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.28:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.29:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.30:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.31:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.32:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.33:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.34:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.35:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.36:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.37:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.38:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.39:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.40:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.41:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.42:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.43:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.44:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.45:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.46:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.47:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.48:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.49:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.50:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.51:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.52:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:4.53:*:*:*:*:*:*:*

History

No history.

Information

Published : 2013-03-08 18:55

Updated : 2024-02-28 12:00


NVD link : CVE-2013-1762

Mitre link : CVE-2013-1762

CVE.ORG link : CVE-2013-1762


JSON object : View

Products Affected

stunnel

  • stunnel
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')