CVE-2002-0002

stunnel < 3.22 - Remote Code Execution via Format String in Client Mode

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0002. PoCs published by deltha.

AI-analyzed exploit summary This exploit targets a format string vulnerability in Stunnel versions 3.3 to 3.21c when using client mode with protocol negotiation options (-n smtp, -n pop, -n nntp). It allows remote code execution by crafting a malicious payload that overwrites memory addresses via format string manipulation.

Description

Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.

Exploits (1)

exploitdb WORKING POC VERIFIED
by deltha · cremotelinux
https://www.exploit-db.com/exploits/21192

This exploit targets a format string vulnerability in Stunnel versions 3.3 to 3.21c when using client mode with protocol negotiation options (-n smtp, -n pop, -n nntp). It allows remote code execution by crafting a malicious payload that overwrites memory addresses via format string manipulation.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Stunnel < 3.22
No auth needed
Prerequisites: Stunnel running in client mode with protocol negotiation options (-n smtp, -n pop, or -n nntp) · Network access to the target Stunnel instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3748
Various Sources vendor-advisory x_refsource_mandrake
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-004.php3
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/248149
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7741
Vendor Advisory x_refsource_confirm
http://stunnel.mirt.net/news.html
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2002-002.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/247427

Scores

EPSS 0.0528
EPSS Percentile 91.5%

Details

Status published
Products (25)
engardelinux/secure_linux 1.0.1
mandrakesoft/mandrake_linux 8.1
redhat/linux 7.2
stunnel/stunnel 3.3
stunnel/stunnel 3.4a
stunnel/stunnel 3.7
stunnel/stunnel 3.8
stunnel/stunnel 3.9
stunnel/stunnel 3.10
stunnel/stunnel 3.11
... and 15 more
Published Jan 31, 2002
Tracked Since Feb 18, 2026