Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.61083
Category:Fedora Local Security Checks
Title:Fedora Core 7 FEDORA-2008-4606 (stunnel)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to stunnel
announced via advisory FEDORA-2008-4606.

Stunnel is a socket wrapper which can provide SSL (Secure Sockets
Layer) support to ordinary applications. For example, it can be used
in conjunction with imapd to create an SSL secure IMAP server.

Update Information:

New upstream release 4.24 fixing security issue in certificate verification via
OCSP protocol: http://stunnel.mirt.net/pipermail/stunnel-
announce/2008-May/000035.html
References:

[ 1 ] Bug #448290 - CVE-2008-2420 stunnel: incorrect CRL verification using OCSP protocol
https://bugzilla.redhat.com/show_bug.cgi?id=448290

Solution: Apply the appropriate updates.

This update can be installed with the yum update program. Use
su -c 'yum update stunnel' at the command line.
For more information, refer to Managing Software with yum,
available at http://docs.fedoraproject.org/yum/.

http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-4606

Risk factor : High

CVSS Score:
6.8

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-2420
BugTraq ID: 29309
http://www.securityfocus.com/bid/29309
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00856.html
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00907.html
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00942.html
http://security.gentoo.org/glsa/glsa-200808-08.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:168
http://stunnel.mirt.net/pipermail/stunnel-announce/2008-May/000035.html
http://secunia.com/advisories/30335
http://secunia.com/advisories/30425
http://secunia.com/advisories/31438
http://www.vupen.com/english/advisories/2008/1569/references
XForce ISS Database: stunnel-ocsp-security-bypass(42528)
https://exchange.xforce.ibmcloud.com/vulnerabilities/42528
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.