stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade net-misc/stunnel. | Oct 30, 2017 | Mar 24, 2014 |
| Oracle Solaris | — | Upgrade service/security/stunnel to version 5.35-0.175.3.16.0.3.0 on Solaris 11.3 | May 29, 2017 | Mar 24, 2014 |
| Suse | — | Upgrade stunnelUpgrade stunnel-openssl1 | Dec 9, 2016 | Mar 24, 2014 |
| Ubuntu | — | Upgrade stunnel4 | Nov 19, 2024 | Mar 24, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub