Hide Forgot
Stunnel 4.42 fixes a heap corruption vulnerability that may be exploited to possibly perform a remote DoS or remote code execution [1]. The upstream changelog indicates that only 4.40 and 4.41 are affected. Fedora 16 has a candidate build of 4.41, which would introduce this flaw; it should be updated to 4.42 immediately. [1] http://stunnel.org/?page=sdf_ChangeLog
Created stunnel tracking bugs for this issue Affects: fedora-rawhide [bug 732069]
This was assigned the name CVE-2011-2940.
Statement: Not vulnerable. This issue did not affect the versions of stunnel as shipped with Red Hat Enterprise Linux 4, 5, or 6.