![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2013-1762 |
Description: | stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.870977 1.3.6.1.4.1.25623.1.0.881712 1.3.6.1.4.1.25623.1.0.121139 1.3.6.1.4.1.25623.1.0.123648 1.3.6.1.4.1.25623.1.1.4.2013.0709.1 1.3.6.1.4.1.25623.1.0.702664 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2013-1762 Debian Security Information: DSA-2664 (Google Search) http://www.debian.org/security/2013/dsa-2664 http://www.mandriva.com/security/advisories?name=MDVSA-2013:130 RedHat Security Advisories: RHSA-2013:0714 http://rhn.redhat.com/errata/RHSA-2013-0714.html |