Lucene search

K
nvd[email protected]NVD:CVE-2003-0740
HistoryOct 20, 2003 - 4:00 a.m.

CVE-2003-0740

2003-10-2004:00:00
web.nvd.nist.gov
4

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

0.4%

Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.

Affected configurations

Nvd
Node
stunnelstunnelMatch3.3
OR
stunnelstunnelMatch3.4a
OR
stunnelstunnelMatch3.7
OR
stunnelstunnelMatch3.8
OR
stunnelstunnelMatch3.9
OR
stunnelstunnelMatch3.10
OR
stunnelstunnelMatch3.11
OR
stunnelstunnelMatch3.12
OR
stunnelstunnelMatch3.13
OR
stunnelstunnelMatch3.14
OR
stunnelstunnelMatch3.15
OR
stunnelstunnelMatch3.16
OR
stunnelstunnelMatch3.17
OR
stunnelstunnelMatch3.18
OR
stunnelstunnelMatch3.19
OR
stunnelstunnelMatch3.20
OR
stunnelstunnelMatch3.21
OR
stunnelstunnelMatch3.21a
OR
stunnelstunnelMatch3.21b
OR
stunnelstunnelMatch3.21c
OR
stunnelstunnelMatch3.22
OR
stunnelstunnelMatch3.24
OR
stunnelstunnelMatch4.0

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

0.4%