CVE
- Id
- 61709
- CVE No.
- CVE-2013-1762
- Status
- Candidate
- Description
- stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.
- Phase
- Assigned (20130219)
- Votes
- None (candidate not yet proposed)
- Comments