marc.info
http://marc.info/?l=stunnel-users&m=100869449828705&w=2 CVE-2002-0002
STunnel 3.x - Client Negotiation Protocol Format String
Record summary
CVE-2002-0002 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSTunnel 3.x - Client Negotiation Protocol Format StringExploitDB exploitby delthaNot analyzed1 file
References
920011227 Stunnel: Format String Bug in versions <3.22mailing list
http://online.securityfocus.com/archive/1/247427 20020102 Stunnel: Format String Bug updatemailing list
http://online.securityfocus.com/archive/1/248149 stunnel.mirt.netConfirmation
http://stunnel.mirt.net/news.html MDKSA-2002:004Vendor advisory
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-004.php3 RHSA-2002:002Vendor advisory
http://www.redhat.com/support/errata/RHSA-2002-002.html 3748vdb entry
http://www.securityfocus.com/bid/3748 stunnel-client-format-string(7741)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/7741 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0002