CVE-2013-1762
Last modified
CVE-2013-1762 is a vulnerability of currently unknown severity. stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.. EPSS estimates a 2.93% chance of exploitation in the next 30 days.
Description
stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Stunnel | Stunnel | <= 4.54 |
| Stunnel | Stunnel | 4.21 |
| Stunnel | Stunnel | 4.22 |
| Stunnel | Stunnel | 4.23 |
| Stunnel | Stunnel | 4.24 |
| Stunnel | Stunnel | 4.25 |
| Stunnel | Stunnel | 4.26 |
| Stunnel | Stunnel | 4.27 |
| Stunnel | Stunnel | 4.28 |
| Stunnel | Stunnel | 4.29 |
| Stunnel | Stunnel | 4.30 |
| Stunnel | Stunnel | 4.31 |
| Stunnel | Stunnel | 4.32 |
| Stunnel | Stunnel | 4.33 |
| Stunnel | Stunnel | 4.34 |
| Stunnel | Stunnel | 4.35 |
| Stunnel | Stunnel | 4.36 |
| Stunnel | Stunnel | 4.37 |
| Stunnel | Stunnel | 4.38 |
| Stunnel | Stunnel | 4.39 |
| Stunnel | Stunnel | 4.40 |
| Stunnel | Stunnel | 4.41 |
| Stunnel | Stunnel | 4.42 |
| Stunnel | Stunnel | 4.43 |
| Stunnel | Stunnel | 4.44 |
| Stunnel | Stunnel | 4.45 |
| Stunnel | Stunnel | 4.46 |
| Stunnel | Stunnel | 4.47 |
| Stunnel | Stunnel | 4.48 |
| Stunnel | Stunnel | 4.49 |
| Stunnel | Stunnel | 4.50 |
| Stunnel | Stunnel | 4.51 |
| Stunnel | Stunnel | 4.52 |
| Stunnel | Stunnel | 4.53 |
References
- https://www.stunnel.org/CVE-2013-1762.htmlVendor Advisory
- https://www.stunnel.org/CVE-2013-1762.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-1762?
How severe is CVE-2013-1762?
How do I fix CVE-2013-1762?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-1752Rejected reason: Various versions of Python do not properly …
- CVE-2013-1753The gzip_decode function in the xmlrpc client library in Pyt…7.5
- CVE-2013-1756The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 f…
- CVE-2013-1758Cross-site scripting (XSS) vulnerability in the Marekkis Wat…
- CVE-2013-1759Cross-site scripting (XSS) vulnerability in the Responsive L…
- CVE-2013-1760The Bug Genie before 3.2.6 has Multiple XSS and HTML Injecti…6.1
- CVE-2013-1763Array index error in the __sock_diag_rcv_msg function in net…
- CVE-2013-1764The Zypper (aka zypp) backend in PackageKit before 0.8.8 all…
- CVE-2013-1765Multiple cross-site scripting (XSS) vulnerabilities in jwpla…
- CVE-2013-1766libvirt 1.0.2 and earlier sets the group owner to kvm for de…
- CVE-2013-1767Use-after-free vulnerability in the shmem_remount_fs functio…
- CVE-2013-1768The BrokerFactory functionality in Apache OpenJPA 1.x before…
Are you affected by CVE-2013-1762?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
