CVE-2001-0060: Critical severity Stunnel Stunnel vulnerability
Published Feb 12, 2001
·Updated
Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.
Affected Software
4 affected components
Stunnel Stunnel=3.7
Stunnel Stunnel=3.3
Stunnel Stunnel=3.4a
Stunnel Stunnel=3.8
Remediation
Patch Available
Patch Available
Event History
Feb 12, 2001
CVE Published
05:00 AM
May 7, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0060?
CVE-2001-0060 has a high severity level due to its potential to allow arbitrary command execution.
2
How do I fix CVE-2001-0060?
To fix CVE-2001-0060, upgrade stunnel to version 3.9 or later.
3
Which versions of stunnel are affected by CVE-2001-0060?
CVE-2001-0060 affects stunnel versions 3.7, 3.3, 3.4a, and 3.8.
4
What kind of attacks can exploit CVE-2001-0060?
CVE-2001-0060 can be exploited to execute arbitrary commands through a crafted ident username.
5
Is CVE-2001-0060 still relevant today?
While CVE-2001-0060 is an older vulnerability, it remains relevant for systems still running affected versions of stunnel.