Upstream information

CVE-2011-2940 at MITRE

Description

stunnel 4.40 and 4.41 might allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

SUSE information

Overall state of this security issue: Ignore

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 9.3
Vector AV:N/AC:M/Au:N/C:C/I:C/A:C
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete

Note from the SUSE Security Team

This issue only affects stunnel 4.40 and 4.41 according to the upstream changelog, so none of our distributions are affected.

SUSE Bugzilla entry: 715641 [RESOLVED / INVALID]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Module for Server Applications 15
  • stunnel >= 5.44-1.29
Patchnames:
SUSE Linux Enterprise Module for Server Applications 15 GA stunnel
openSUSE Tumbleweed
  • stunnel >= 5.38-1.1
  • stunnel-doc >= 5.38-1.1
Patchnames:
openSUSE Tumbleweed GA stunnel