CVE Vulnerabilities

CVE-2001-0060

Published: Feb 12, 2001 | Modified: May 03, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.

Affected Software

Name Vendor Start Version End Version
Stunnel Stunnel 3.3 (including) 3.3 (including)
Stunnel Stunnel 3.4a (including) 3.4a (including)
Stunnel Stunnel 3.7 (including) 3.7 (including)
Stunnel Stunnel 3.8 (including) 3.8 (including)

References