CVE-2003-0740: Medium severity Stunnel Stunnel vulnerability
Published Sep 4, 2003
·Updated
Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.
Affected Software
23 affected components
Stunnel Stunnel=3.21c
Stunnel Stunnel=3.7
Stunnel Stunnel=3.3
Stunnel Stunnel=3.21b
Stunnel Stunnel=3.14
Stunnel Stunnel=3.4a
Stunnel Stunnel=3.22
Stunnel Stunnel=3.18
Stunnel Stunnel=3.20
Stunnel Stunnel=3.10
Stunnel Stunnel=3.11
Stunnel Stunnel=3.19
Stunnel Stunnel=3.16
Stunnel Stunnel=3.17
Stunnel Stunnel=3.24
Stunnel Stunnel=3.12
Stunnel Stunnel=3.13
Stunnel Stunnel=3.21
Stunnel Stunnel=3.8
Stunnel Stunnel=3.15
Stunnel Stunnel=3.21a
Stunnel Stunnel=3.9
Stunnel Stunnel=4.0
Event History
Sep 4, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Oct 20, 2003
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0740?
CVE-2003-0740 is classified as a critical vulnerability due to its potential for local users to hijack the Stunnel server.
2
How do I fix CVE-2003-0740?
To mitigate CVE-2003-0740, upgrade Stunnel to version 4.1 or later to ensure the privileged file descriptor leak is addressed.
3
What software versions are affected by CVE-2003-0740?
CVE-2003-0740 affects Stunnel versions 4.0 and earlier, including 3.24 and lower versions.
4
What are the consequences of CVE-2003-0740?
Exploitation of CVE-2003-0740 allows local users to gain unauthorized access and control over the Stunnel service.
5
Is CVE-2003-0740 related to remote access vulnerabilities?
CVE-2003-0740 is not a remote access vulnerability; it specifically enables local user exploitation of the Stunnel server.