CVE-2015-3644
Debian Security Advisory 3299-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers to bypass authentication.
Stunnel 5.00 hasta 5.13, cuando utiliza la opción de redirección, no redirige las conexiones de clientes al servidor esperado después de la conexión inicial, lo que permite a atacantes remotos evadir la autenticación.
Johan Olofsson discovered an authentication bypass vulnerability in Stunnel, a program designed to work as an universal SSL tunnel for network daemons. When Stunnel in server mode is used with the redirect option and certificate-based authentication is enabled with "verify = 2" or higher, then only the initial connection is redirected to the hosts specified with "redirect". This allows a remote attacker to bypass authentication.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-05-04 CVE Reserved
- 2015-05-14 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/74659 | Vdb Entry | |
http://www.securitytracker.com/id/1032324 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.stunnel.org/CVE-2015-3644.html | 2016-12-28 |
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2015/dsa-3299 | 2016-12-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 5.00 Search vendor "Stunnel" for product "Stunnel" and version "5.00" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 5.01 Search vendor "Stunnel" for product "Stunnel" and version "5.01" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 5.02 Search vendor "Stunnel" for product "Stunnel" and version "5.02" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 5.03 Search vendor "Stunnel" for product "Stunnel" and version "5.03" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 5.04 Search vendor "Stunnel" for product "Stunnel" and version "5.04" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 5.05 Search vendor "Stunnel" for product "Stunnel" and version "5.05" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 5.06 Search vendor "Stunnel" for product "Stunnel" and version "5.06" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 5.07 Search vendor "Stunnel" for product "Stunnel" and version "5.07" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 5.08 Search vendor "Stunnel" for product "Stunnel" and version "5.08" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 5.09 Search vendor "Stunnel" for product "Stunnel" and version "5.09" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 5.10 Search vendor "Stunnel" for product "Stunnel" and version "5.10" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 5.11 Search vendor "Stunnel" for product "Stunnel" and version "5.11" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 5.12 Search vendor "Stunnel" for product "Stunnel" and version "5.12" | - |
Affected
| ||||||
Stunnel Search vendor "Stunnel" | Stunnel Search vendor "Stunnel" for product "Stunnel" | 5.13 Search vendor "Stunnel" for product "Stunnel" and version "5.13" | - |
Affected
|