SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-1762

stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer…

MEDIUM 6.6EPSS 2.93%

Does this matter?

Lower severity and a low EPSS score (2.93%). Track it; it rarely justifies an emergency change on its own.

Description

stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.

CVSS 2.0
6.6 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:C
EPSS
2.93% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
stunnel/stunnel
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.