CVE-2003-0740

Description

Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.

Risk Information

Base Score
5.9
MODERATE
Vector
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.116

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in stunnel 3.3Windows
Multiple Vulnerabilities are affected in stunnel 3.4aWindows
Multiple Vulnerabilities are affected in stunnel 3.7Windows
Multiple Vulnerabilities are affected in stunnel 3.8Windows
Multiple Vulnerabilities are affected in stunnel 3.10Windows
Multiple Vulnerabilities are affected in stunnel 3.11Windows
Multiple Vulnerabilities are affected in stunnel 3.12Windows
Multiple Vulnerabilities are affected in stunnel 3.13Windows
Multiple Vulnerabilities are affected in stunnel 3.14Windows
Multiple Vulnerabilities are affected in stunnel 3.15Windows
Multiple Vulnerabilities are affected in stunnel 3.16Windows
Multiple Vulnerabilities are affected in stunnel 3.17Windows
Multiple Vulnerabilities are affected in stunnel 3.18Windows
Multiple Vulnerabilities are affected in stunnel 3.19Windows
Multiple Vulnerabilities are affected in stunnel 3.20Windows
Multiple Vulnerabilities are affected in stunnel 3.21Windows
Multiple Vulnerabilities are affected in stunnel 3.21aWindows
Multiple Vulnerabilities are affected in stunnel 3.21bWindows
Multiple Vulnerabilities are affected in stunnel 3.21cWindows
Multiple Vulnerabilities are affected in stunnel 3.22Windows
Multiple Vulnerabilities are affected in stunnel 3.24Windows
Multiple Vulnerabilities are affected in stunnel 3.9Windows
Vulnerabilities CVE-2003-0147,CVE-2003-0740,CVE-2008-2400,CVE-2014-0016 are affected in stunnel 4.0Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)
PATCH-348313stunnel (5.75)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234