CVE-2013-1762
Description
stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.01
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.21 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.22 | Windows |
| Vulnerabilities CVE-2008-2420,CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.23 | Windows |
| Vulnerabilities CVE-2011-2940,CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.40 | Windows |
| Vulnerabilities CVE-2011-2940,CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.41 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.24 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.25 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.26 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.27 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.28 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.29 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.30 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.31 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.32 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.33 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.34 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.35 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.36 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.37 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.38 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.39 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.42 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.43 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.44 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.45 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.46 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.47 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.48 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.49 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.50 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.51 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.52 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.53 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.54 | Windows |
| stunnel4 security update(DSA-2664-1) stunnel4_4.53-1.1_i386.deb | Linux |
| (RHSA-2013:0714) Moderate: stunnel security update stunnel-4.29-3.el6_4.i686.rpm | Linux |
| (RHSA-2013:0714) Moderate: stunnel security update stunnel-4.29-3.el6_4.x86_64.rpm | Linux |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234