Rapid7 Vulnerability & Exploit Database

CESA-2003:297: stunnel security update

Back to Search

CESA-2003:297: stunnel security update

Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
10/20/2003
Created
07/25/2018
Added
03/12/2010
Modified
07/04/2017

Description

Updated stunnel packages are now available. These updates address problems stemming from improper use of non-reentrant functions in signal handlers.

Stunnel is a wrapper for network connections. It can be used to tunnel an unencrypted network connection over an encrypted connection (encrypted using SSL or TLS) or to provide an encrypted means of connecting to services that do not natively support encryption. A previous advisory provided updated packages to address re-entrancy problems in stunnel's signal-handling routines. These updates did not address other bugs that were found by Steve Grubb, and introduced an additional bug, which was fixed in stunnel 3.26. All users should upgrade to these errata packages, which address these issues by updating stunnel to version 3.26. NOTE: After upgrading, any instances of stunnel configured to run in daemon mode should be restarted, and any active network connections that are currently being serviced by stunnel should be terminated and reestablished.

Solution(s)

  • centos-upgrade-stunnel

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;