CVE-2014-0016
Last modified
CVE-2014-0016 is a vulnerability of currently unknown severity. stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.. EPSS estimates a 2.15% chance of exploitation in the next 30 days.
Description
stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Stunnel | Stunnel | <= 4.56 |
| Stunnel | Stunnel | 0.1 |
| Stunnel | Stunnel | 1.0 |
| Stunnel | Stunnel | 1.1 |
| Stunnel | Stunnel | 1.2 |
| Stunnel | Stunnel | 1.3 |
| Stunnel | Stunnel | 1.4 |
| Stunnel | Stunnel | 1.5 |
| Stunnel | Stunnel | 1.6 |
| Stunnel | Stunnel | 2.0 |
| Stunnel | Stunnel | 2.1 |
| Stunnel | Stunnel | 3.0 |
| Stunnel | Stunnel | 3.1 |
| Stunnel | Stunnel | 3.2 |
| Stunnel | Stunnel | 3.3 |
| Stunnel | Stunnel | 3.4a |
| Stunnel | Stunnel | 3.5 |
| Stunnel | Stunnel | 3.6 |
| Stunnel | Stunnel | 3.7 |
| Stunnel | Stunnel | 3.8 |
| Stunnel | Stunnel | 3.8p1 |
| Stunnel | Stunnel | 3.8p2 |
| Stunnel | Stunnel | 3.8p3 |
| Stunnel | Stunnel | 3.8p4 |
| Stunnel | Stunnel | 3.9 |
| Stunnel | Stunnel | 3.10 |
| Stunnel | Stunnel | 3.11 |
| Stunnel | Stunnel | 3.12 |
| Stunnel | Stunnel | 3.13 |
| Stunnel | Stunnel | 3.14 |
| Stunnel | Stunnel | 3.15 |
| Stunnel | Stunnel | 3.16 |
| Stunnel | Stunnel | 3.17 |
| Stunnel | Stunnel | 3.18 |
| Stunnel | Stunnel | 3.19 |
| Stunnel | Stunnel | 3.20 |
| Stunnel | Stunnel | 3.21 |
| Stunnel | Stunnel | 3.21a |
| Stunnel | Stunnel | 3.21b |
| Stunnel | Stunnel | 3.21c |
| Stunnel | Stunnel | 3.22 |
| Stunnel | Stunnel | 3.23 |
| Stunnel | Stunnel | 3.24 |
| Stunnel | Stunnel | 3.25 |
| Stunnel | Stunnel | 3.26 |
| Stunnel | Stunnel | 4.00 |
| Stunnel | Stunnel | 4.0 |
| Stunnel | Stunnel | 4.01 |
| Stunnel | Stunnel | 4.02 |
| Stunnel | Stunnel | 4.03 |
Showing 50 of 102 affected configurations. See NVD for the full list.
References
- http://www.openwall.com/lists/oss-security/2014/03/05/1Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/65964Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1072180Issue Tracking, Third Party Advisory, VDB Entry
- https://www.stunnel.org/sdf_ChangeLog.htmlRelease Notes, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2014/03/05/1Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/65964Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1072180Issue Tracking, Third Party Advisory, VDB Entry
- https://www.stunnel.org/sdf_ChangeLog.htmlRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-0016?
How severe is CVE-2014-0016?
How do I fix CVE-2014-0016?
Are you affected by CVE-2014-0016?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
