Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.
description | Stunnel <= 3.24, 4.00 Daemon Hijacking Proof of Concept Exploit. CVE-2003-0740. Local exploit for linux platform |
id | EDB-ID:91 |
last seen | 2016-01-31 |
modified | 2003-09-05 |
published | 2003-09-05 |
reporter | Steve Grubb |
source | |
title | Stunnel <= 3.24/4.00 - Daemon Hijacking Proof of Concept Exploit |
Stunnel is a wrapper for network connections. It can be used to tunnel an unencrypted network connection over an encrypted connection (encrypted using SSL or TLS) or to provide an encrypted means of connecting to services that do not natively support encryption. A previous advisory provided updated packages to address re-entrancy problems in stunnel 