CVE-2013-1762

Priority
Description
stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM
authentication are enabled, does not correctly perform integer conversion,
which allows remote proxy servers to execute arbitrary code via a crafted
request that triggers a buffer overflow.
Assigned-to
mdeslaur
Notes
Package
Upstream:released (4.55,3:4.53-1.1)
Ubuntu 22.04 LTS (Jammy Jellyfish):not-affected (3:4.53-1.1ubuntu1)
Patches:
More Information

Updated: 2022-02-11 00:29:54 UTC (commit acb3d89ab51f1d5e5543fa993969c0eb13c71f04)