Id:
CVE-2013-1762
Comment
:
stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.
CVSSv2 Score:
6.6
Access vector:
|
COMPLETE
|
Access complexity:
|
HIGH
|
Authentication:
|
NONE
|
Confidentiality impact:
|
PARTIAL
|
Integrity impact:
|
PARTIAL
|
Availability impact:
|
COMPLETE
|
CVSSv2 Vector:
AV:N/AC:H/Au:N/C:P/I:P/A:C
References: