7.5

CVE-2002-0002

Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Stunnel ≫ Stunnel Version 3.3
Stunnel ≫ Stunnel Version 3.4a
Stunnel ≫ Stunnel Version 3.7
Stunnel ≫ Stunnel Version 3.8
Stunnel ≫ Stunnel Version 3.9
Stunnel ≫ Stunnel Version 3.10
Stunnel ≫ Stunnel Version 3.11
Stunnel ≫ Stunnel Version 3.12
Stunnel ≫ Stunnel Version 3.13
Stunnel ≫ Stunnel Version 3.14
Stunnel ≫ Stunnel Version 3.15
Stunnel ≫ Stunnel Version 3.16
Stunnel ≫ Stunnel Version 3.17
Stunnel ≫ Stunnel Version 3.18
Stunnel ≫ Stunnel Version 3.19
Stunnel ≫ Stunnel Version 3.20
Stunnel ≫ Stunnel Version 3.21
Stunnel ≫ Stunnel Version 3.21a
Stunnel ≫ Stunnel Version 3.21b
Stunnel ≫ Stunnel Version 3.21c
Stunnel ≫ Stunnel Version 3.22
Stunnel ≫ Stunnel Version 3.24
Engardelinux ≫ Secure Linux Version 1.0.1
Mandrakesoft ≫ Mandrake Linux Version 8.1
Redhat ≫ Linux Version 7.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.28% 0.915
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=stunnel-users&m=100869449828705&w=2
http://online.securityfocus.com/archive/1/247427
http://online.securityfocus.com/archive/1/248149
http://stunnel.mirt.net/news.html
Vendor Advisory
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-004.php3
http://www.redhat.com/support/errata/RHSA-2002-002.html
Patch
Vendor Advisory
http://www.securityfocus.com/bid/3748
https://exchange.xforce.ibmcloud.com/vulnerabilities/7741