CVE Vulnerabilities

CVE-2002-0002

Published: Jan 31, 2002 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.

Affected Software

Name Vendor Start Version End Version
Stunnel Stunnel 3.21c 3.21c
Stunnel Stunnel 3.7 3.7
Stunnel Stunnel 3.3 3.3
Stunnel Stunnel 3.21b 3.21b
Stunnel Stunnel 3.14 3.14
Stunnel Stunnel 3.4a 3.4a
Stunnel Stunnel 3.22 3.22
Stunnel Stunnel 3.18 3.18
Stunnel Stunnel 3.20 3.20
Stunnel Stunnel 3.15 3.15
Stunnel Stunnel 3.24 3.24
Stunnel Stunnel 3.11 3.11
Stunnel Stunnel 3.8 3.8
Stunnel Stunnel 3.21 3.21
Stunnel Stunnel 3.13 3.13
Stunnel Stunnel 3.17 3.17
Stunnel Stunnel 3.10 3.10
Stunnel Stunnel 3.16 3.16
Stunnel Stunnel 3.9 3.9
Stunnel Stunnel 3.12 3.12
Stunnel Stunnel 3.21a 3.21a
Stunnel Stunnel 3.19 3.19

References