← Back

CVE-2014-0016

nvd nist
Published: Mar 24, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.

Affected (113)

Products: Stunnel: Stunnel
1 product
Stunnel
Configuration A
113 vulnerable
Vulnerable SoftwareAffected Versions
Stunnel
Up to 4.56
Version 0.1
Version 1.0
Version 1.1
Version 1.2
Version 1.3
Version 1.4
Version 1.5
Version 1.6
Version 2.0
Version 2.1
Version 3.0
Version 3.0 b1
Version 3.0 b2
Version 3.0 b3
Version 3.0 b4
Version 3.0 b5
Version 3.0 b6
Version 3.0 b7
Version 3.10
Version 3.11
Version 3.12
Version 3.13
Version 3.14
Version 3.15
Version 3.16
Version 3.17
Version 3.18
Version 3.19
Version 3.1
Version 3.20
Version 3.21
Version 3.21a
Version 3.21b
Version 3.21c
Version 3.22
Version 3.23
Version 3.24
Version 3.25
Version 3.26
Version 3.2
Version 3.3
Version 3.4a
Version 3.5
Version 3.6
Version 3.7
Version 3.8
Version 3.8 p1
Version 3.8 p2
Version 3.8 p3
Version 3.8 p4
Version 3.8p1
Version 3.8p2
Version 3.8p3
Version 3.8p4
Version 3.9
Version 4.00
Version 4.01
Version 4.02
Version 4.03
Version 4.04
Version 4.05
Version 4.06
Version 4.07
Version 4.08
Version 4.09
Version 4.0
Version 4.10
Version 4.11
Version 4.12
Version 4.13
Version 4.14
Version 4.15
Version 4.16
Version 4.17
Version 4.18
Version 4.19
Version 4.20
Version 4.21
Version 4.22
Version 4.23
Version 4.24
Version 4.25
Version 4.26
Version 4.27
Version 4.28
Version 4.29
Version 4.30
Version 4.31
Version 4.32
Version 4.33
Version 4.34
Version 4.35
Version 4.36
Version 4.37
Version 4.38
Version 4.39
Version 4.40
Version 4.41
Version 4.42
Version 4.43
Version 4.44
Version 4.45
Version 4.46
Version 4.47
Version 4.48
Version 4.49
Version 4.50
Version 4.51
Version 4.52
Version 4.53
Version 4.54
Version 4.55

References (10)

Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Issue TrackingThird Party AdvisoryVDB Entry
Source: secalert@redhat.com
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.