SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-0016

stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers…

MEDIUM 4.3EPSS 2.15%

Does this matter?

Lower severity and a low EPSS score (2.15%). Track it; it rarely justifies an emergency change on its own.

Description

stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
2.15% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-332
Affected
stunnel/stunnel
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.