CVE-2014-0016
Last modified
CVE-2014-0016 is a vulnerability of currently unknown severity. stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.. EPSS estimates a 2.15% chance of exploitation in the next 30 days.
Description
stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Stunnel | Stunnel | <= 4.56 |
| Stunnel | Stunnel | 0.1 |
| Stunnel | Stunnel | 1.0 |
| Stunnel | Stunnel | 1.1 |
| Stunnel | Stunnel | 1.2 |
| Stunnel | Stunnel | 1.3 |
| Stunnel | Stunnel | 1.4 |
| Stunnel | Stunnel | 1.5 |
| Stunnel | Stunnel | 1.6 |
| Stunnel | Stunnel | 2.0 |
| Stunnel | Stunnel | 2.1 |
| Stunnel | Stunnel | 3.0 |
| Stunnel | Stunnel | 3.1 |
| Stunnel | Stunnel | 3.2 |
| Stunnel | Stunnel | 3.3 |
| Stunnel | Stunnel | 3.4a |
| Stunnel | Stunnel | 3.5 |
| Stunnel | Stunnel | 3.6 |
| Stunnel | Stunnel | 3.7 |
| Stunnel | Stunnel | 3.8 |
| Stunnel | Stunnel | 3.8p1 |
| Stunnel | Stunnel | 3.8p2 |
| Stunnel | Stunnel | 3.8p3 |
| Stunnel | Stunnel | 3.8p4 |
| Stunnel | Stunnel | 3.9 |
| Stunnel | Stunnel | 3.10 |
| Stunnel | Stunnel | 3.11 |
| Stunnel | Stunnel | 3.12 |
| Stunnel | Stunnel | 3.13 |
| Stunnel | Stunnel | 3.14 |
| Stunnel | Stunnel | 3.15 |
| Stunnel | Stunnel | 3.16 |
| Stunnel | Stunnel | 3.17 |
| Stunnel | Stunnel | 3.18 |
| Stunnel | Stunnel | 3.19 |
| Stunnel | Stunnel | 3.20 |
| Stunnel | Stunnel | 3.21 |
| Stunnel | Stunnel | 3.21a |
| Stunnel | Stunnel | 3.21b |
| Stunnel | Stunnel | 3.21c |
| Stunnel | Stunnel | 3.22 |
| Stunnel | Stunnel | 3.23 |
| Stunnel | Stunnel | 3.24 |
| Stunnel | Stunnel | 3.25 |
| Stunnel | Stunnel | 3.26 |
| Stunnel | Stunnel | 4.00 |
| Stunnel | Stunnel | 4.0 |
| Stunnel | Stunnel | 4.01 |
| Stunnel | Stunnel | 4.02 |
| Stunnel | Stunnel | 4.03 |
Showing 50 of 102 affected configurations. See NVD for the full list.
References
- http://www.openwall.com/lists/oss-security/2014/03/05/1Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/65964Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1072180Issue Tracking, Third Party Advisory, VDB Entry
- https://www.stunnel.org/sdf_ChangeLog.htmlRelease Notes, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2014/03/05/1Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/65964Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1072180Issue Tracking, Third Party Advisory, VDB Entry
- https://www.stunnel.org/sdf_ChangeLog.htmlRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-0016?
How severe is CVE-2014-0016?
How do I fix CVE-2014-0016?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-0010Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2014-0011Multiple heap-based buffer overflows in the ZRLE_DECODE func…9.8
- CVE-2014-0012FileSystemBytecodeCache in Jinja2 2.7.2 does not properly cr…
- CVE-2014-0013Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x befor…
- CVE-2014-0014Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x befor…
- CVE-2014-0015cURL and libcurl 7.10.6 through 7.34.0, when more than one a…
- CVE-2014-0017The RAND_bytes function in libssh before 0.6.3, when forking…
- CVE-2014-0018Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 …
- CVE-2014-0019Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2…
- CVE-2014-0020The IRC protocol plugin in libpurple in Pidgin before 2.10.8…
- CVE-2014-0021Chrony before 1.29.1 has traffic amplification in cmdmon pro…7.5
- CVE-2014-0022The installUpdates function in yum-cron/yum-cron.py in yum 3…
Are you affected by CVE-2014-0016?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
