CVE-2014-0016
Description
stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.
Risk Information
Base Score
5.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.312
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in stunnel 3.3 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.4a | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.7 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.8 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.10 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.11 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.12 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.13 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.14 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.15 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.16 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.17 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.18 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.19 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.20 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.21 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.21a | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.21b | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.21c | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.22 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.24 | Windows |
| Multiple Vulnerabilities are affected in stunnel 3.9 | Windows |
| Multiple Vulnerabilities are affected in stunnel 4.04 | Windows |
| Vulnerabilities CVE-2003-0147,CVE-2003-0740,CVE-2008-2400,CVE-2014-0016 are affected in stunnel 4.0 | Windows |
| Vulnerabilities CVE-2003-0147,CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.01 | Windows |
| Vulnerabilities CVE-2003-0147,CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.02 | Windows |
| Vulnerabilities CVE-2003-0147,CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.03 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 0.1 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 1.0 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 1.1 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 1.2 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 1.3 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 1.4 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 1.5 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 1.6 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 2.0 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 2.1 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 3.0 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 3.0-b1 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 3.0-b2 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 3.0-b3 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 3.0-b4 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 3.0-b5 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 3.0-b6 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 3.0-b7 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 3.1 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2014-0016 are affected in stunnel 3.2 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.5 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.6 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.05 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.06 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.07 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.08 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.09 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.10 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.11 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.12 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.13 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.14 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.15 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.16 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.17 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.18 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.19 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.20 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.21 | Windows |
| Vulnerabilities CVE-2008-2400,CVE-2008-2420,CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.22 | Windows |
| Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.23 | Windows |
| Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.25 | Windows |
| Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.26 | Windows |
| Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.8p1 | Windows |
| Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.8p2 | Windows |
| Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.8p3 | Windows |
| Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 3.8p4 | Windows |
| Vulnerabilities CVE-2008-2420,CVE-2014-0016 are affected in stunnel 4.00 | Windows |
| Vulnerabilities CVE-2008-2420,CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.23 | Windows |
| Vulnerabilities CVE-2011-2940,CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.40 | Windows |
| Vulnerabilities CVE-2011-2940,CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.41 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.24 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.25 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.26 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.27 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.28 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.29 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.30 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.31 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.32 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.33 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.34 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.35 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.36 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.37 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.38 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.39 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.42 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.43 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.44 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.45 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.46 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.47 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.48 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.49 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.50 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.51 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.52 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.53 | Windows |
| Vulnerabilities CVE-2013-1762,CVE-2014-0016 are affected in stunnel 4.54 | Windows |
| Vulnerabilities CVE-2014-0016 are affected in stunnel 4.55 | Windows |
| Vulnerabilities CVE-2014-0016 are affected in stunnel 4.56 | Windows |
| Insufficient Entropy in PRNG Vulnerability (CVE-2014-0016) | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
| PATCH-348313 | stunnel (5.75) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234