CVE-2014-0016
N/A
N/A
Summary
stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://www.stunnel.org/sdf_ChangeLog.html
- https://bugzilla.redhat.com/attachment.cgi?id=870826&action=diff
- http://www.openwall.com/lists/oss-security/2014/03/05/1
- https://bugzilla.redhat.com/show_bug.cgi?id=1072180
- http://www.securityfocus.com/bid/65964
References
- https://www.stunnel.org/sdf_ChangeLog.html
- https://bugzilla.redhat.com/attachment.cgi?id=870826&action=diff
- http://www.openwall.com/lists/oss-security/2014/03/05/1
- https://bugzilla.redhat.com/show_bug.cgi?id=1072180
- http://www.securityfocus.com/bid/65964
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.