CVE-2013-1762: Code Injection
Published Mar 8, 2013
·Updated
stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.
Affected Software
34 affected components
Stunnel Stunnel<=4.54
Stunnel Stunnel=4.21
Stunnel Stunnel=4.22
Stunnel Stunnel=4.23
Stunnel Stunnel=4.24
Stunnel Stunnel=4.25
Stunnel Stunnel=4.26
Stunnel Stunnel=4.27
Stunnel Stunnel=4.28
Stunnel Stunnel=4.29
Stunnel Stunnel=4.30
Stunnel Stunnel=4.31
Stunnel Stunnel=4.32
Stunnel Stunnel=4.33
Stunnel Stunnel=4.34
Stunnel Stunnel=4.35
Stunnel Stunnel=4.36
Stunnel Stunnel=4.37
Stunnel Stunnel=4.38
Stunnel Stunnel=4.39
Stunnel Stunnel=4.40
Stunnel Stunnel=4.41
Stunnel Stunnel=4.42
Stunnel Stunnel=4.43
Stunnel Stunnel=4.44
Stunnel Stunnel=4.45
Stunnel Stunnel=4.46
Stunnel Stunnel=4.47
Stunnel Stunnel=4.48
Stunnel Stunnel=4.49
Stunnel Stunnel=4.50
Stunnel Stunnel=4.51
Stunnel Stunnel=4.52
Stunnel Stunnel=4.53
Event History
Mar 8, 2013
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1762?
CVE-2013-1762 is classified as a critical vulnerability due to the potential for remote code execution via a buffer overflow.
2
How do I fix CVE-2013-1762?
To mitigate CVE-2013-1762, upgrade stunnel to version 4.55 or newer where the vulnerability is patched.
3
Which versions of stunnel are affected by CVE-2013-1762?
CVE-2013-1762 affects stunnel versions 4.21 through 4.54.
4
What type of attack is possible due to CVE-2013-1762?
CVE-2013-1762 allows remote proxy servers to execute arbitrary code through crafted requests.
5
What features need to be enabled for CVE-2013-1762 to be exploitable?
CVE-2013-1762 is exploitable when CONNECT protocol negotiation and NTLM authentication are enabled.