A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redirect and verifyChain options. This flaw allows an attacker with a certificate signed by a Certificate Authority, which is not the one accepted by the stunnel server, to access the tunneled service instead of being redirected to the address specified in the redirect option. The highest threat from this vulnerability is to confidentiality.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade stunnel | May 4, 2022 | Feb 23, 2021 |
| Centos_linux | — | Upgrade stunnelUpgrade stunnel-debuginfoUpgrade stunnel-debugsource | Feb 23, 2021 | Feb 22, 2021 |
| Debian | — | Upgrade stunnel4 | Jul 30, 2024 | Feb 23, 2021 |
| Gentoo Linux | — | Upgrade net-misc/stunnel. | May 28, 2021 | Feb 23, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade stunnel | May 18, 2021 | Feb 23, 2021 |
| Oracle Solaris | — | Upgrade service/security/stunnel to version 5.59-11.4.36.0.1.101.0 on Solaris 11.4 | Aug 27, 2021 | Feb 23, 2021 |
| Oracle_linux | — | Upgrade stunnel | Feb 24, 2021 | Oct 11, 2020 |
| Redhat_linux | — | Upgrade stunnel-debugsourceUpgrade stunnelUpgrade stunnel-debuginfo | Feb 23, 2021 | Feb 22, 2021 |
| Rocky_linux | — | Upgrade stunnelUpgrade stunnel-debugsourceUpgrade stunnel-debuginfo | Mar 12, 2024 | Feb 23, 2021 |
| Suse | — | Upgrade stunnel-docUpgrade stunnel | Mar 16, 2021 | Feb 23, 2021 |
| Ubuntu | — | Upgrade stunnel4 (Ubuntu Pro)Upgrade stunnel4 | Jul 19, 2024 | Feb 23, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub