stunnel: Arbitrary code execution — GLSA 201202-08

A vulnerability was found in stunnel, allowing remote attackers to cause a Denial of Service and potentially arbitrary code execution.

Affected packages

net-misc/stunnel on all architectures
Affected versions < 4.44
Unaffected versions >= 4.44
< 4

Background

The stunnel program is designed to work as an SSL encryption wrapper between a client and a local or remote server.

Description

An unspecified heap vulnerability was discovered in stunnel.

Impact

The vulnerability may possibly be leveraged to perform remote code execution or a Denial of Service attack.

Workaround

There is no known workaround at this time.

Resolution

All stunnel 4.x users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-misc/stunnel-4.44"
 

References

Release date
February 29, 2012

Latest revision
July 30, 2012: 2

Severity
normal

Exploitable
remote

Bugzilla entries