Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2013-1762
Description:stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.
Test IDs: 1.3.6.1.4.1.25623.1.0.870977   1.3.6.1.4.1.25623.1.0.881712   1.3.6.1.4.1.25623.1.0.121139   1.3.6.1.4.1.25623.1.0.123648   1.3.6.1.4.1.25623.1.1.4.2013.0709.1   1.3.6.1.4.1.25623.1.0.702664  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2013-1762
Debian Security Information: DSA-2664 (Google Search)
http://www.debian.org/security/2013/dsa-2664
http://www.mandriva.com/security/advisories?name=MDVSA-2013:130
RedHat Security Advisories: RHSA-2013:0714
http://rhn.redhat.com/errata/RHSA-2013-0714.html




© 1998-2025 E-Soft Inc. All rights reserved.