CVE-2013-1762
CVE-2013-1762 is a medium-severity vulnerability in Stunnel with a CVSS 2.0 base score of 6.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-94.
Key facts
- Severity: Medium (CVSS 2.0 base score 6.6)
- EPSS exploit prediction: 3% (87th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Stunnel
- Published:
- Last modified:
Description
stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.
Frequently asked questions
- What is CVE-2013-1762?
- stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.
- How severe is CVE-2013-1762?
- CVE-2013-1762 has a CVSS 2.0 base score of 6.6, rated medium severity.
- Is CVE-2013-1762 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (87th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2013-1762?
- CVE-2013-1762 primarily affects Stunnel. In total, 34 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2013-1762?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2013-1762 published?
- CVE-2013-1762 was published on 2013-03-08 and last updated on 2026-06-16.
References
- http://rhn.redhat.com/errata/RHSA-2013-0714.html
- http://www.debian.org/security/2013/dsa-2664
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:130
- https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0097
- https://www.stunnel.org/CVE-2013-1762.html
Affected products (34)
- cpe:2.3:a:stunnel:stunnel:*:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.21:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.22:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.23:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.24:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.25:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.26:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.27:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.28:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.29:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.30:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.31:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.32:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.33:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.34:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.35:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.36:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.37:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.38:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.39:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.40:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.41:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.42:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.43:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.44:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.45:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.46:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.47:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.48:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.49:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.50:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.51:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.52:*:*:*:*:*:*:*
- cpe:2.3:a:stunnel:stunnel:4.53:*:*:*:*:*:*:*
More vulnerabilities in Stunnel
- CVE-2001-0060 — Critical (CVSS 10.0): Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed…
- CVE-2011-2940 — Critical (CVSS 9.3): stunnel 4.40 and 4.41 might allow remote attackers to execute arbitrary code or cause a denial of service (heap memory…
- CVE-2021-20230 — High (CVSS 7.5): A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use…
- CVE-2002-0002 — High (CVSS 7.5): Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows…
- CVE-2008-2400 — High (CVSS 7.2): Unspecified vulnerability in stunnel before 4.23, when running as a service on Windows, allows local users to gain…
- CVE-2008-2420 — Medium (CVSS 6.8): The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows…
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-105857 — Critical (CVSS 10.0): Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions…
- CVE-2026-55107 — Critical (CVSS 10.0): Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted…
- CVE-2026-96349 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
- CVE-2026-102425 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa…
- CVE-2026-89275 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…
- CVE-2026-84412 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…