Bug 917839 (CVE-2013-1762) - CVE-2013-1762 Stunnel: buffer overflow vulnerability due to incorrect integer conversion in the NTLM authentication of the CONNECT protocol negotiation
Summary: CVE-2013-1762 Stunnel: buffer overflow vulnerability due to incorrect integer...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2013-1762
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 917869 917870
Blocks: 917842
TreeView+ depends on / blocked
 
Reported: 2013-03-04 21:59 UTC by Kurt Seifried
Modified: 2021-02-17 07:58 UTC (History)
6 users (show)

Fixed In Version: stunnel-4.55
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-04-08 19:05:07 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2013:0714 0 normal SHIPPED_LIVE Moderate: stunnel security update 2013-04-08 21:48:25 UTC

Description Kurt Seifried 2013-03-04 21:59:51 UTC
Michal Trojnara reports:

A buffer overflow vulnerability due to incorrect integer conversion in the NTLM authentication of the CONNECT protocol negotiation
Exploitability

The vulnerability is exploitable under the following conditions:
-Stunnel versions 4.21 until 4.54.
-Stunnel compiled as a 64-bit executable. Any 32-bit builds, including pre-compiled Win32 binaries, are not vulnerable.
-Service configured in SSL client mode ("client = yes").
-CONNECT protocol negotiation enabled ("protocol = connect").
-NTLM authentication enabled ("protocolAuthentication = NTLM").
-The attacker able either to control the proxy server specified as a parameter of the "connect" option, or to perform MITM attacks on TCP sessions between stunnel and the proxy server.

Impact

The vulnerability may be exploited for arbitrary code execution. The code is executed within the configured chroot directory, with privileges of the configured user and group.

Recommendation

Upgrade to stunnel 4.55, or disable the NTLM authentication.

Credits

Vulnerability discovery: Mateusz Kocielski, LogicalTrust

External urls:
https://www.stunnel.org/CVE-2013-1762.html

Comment 6 Jan Lieskovsky 2013-03-22 13:00:02 UTC
(In reply to comment #0)
>
> Recommendation
> 
> Upgrade to stunnel 4.55, or disable the NTLM authentication.
> 

This issue does NOT affect the versions of the stunnel package, as shipped with Fedora release of 17 and 18 - the stunnel-4.55-1.fc17 and stunnel-4.55-1.fc18 versions (which contain the fix for this issue) has been pushed to particular Fedora release -testing repository already:

  https://admin.fedoraproject.org/updates/stunnel-4.55-1.fc17
  https://admin.fedoraproject.org/updates/stunnel-4.55-1.fc18

Comment 14 Vincent Danen 2013-04-08 17:12:06 UTC
External Reference:

https://www.stunnel.org/CVE-2013-1762.html

Comment 15 errata-xmlrpc 2013-04-08 17:49:51 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2013:0714 https://rhn.redhat.com/errata/RHSA-2013-0714.html

Comment 16 Vincent Danen 2013-04-08 19:05:07 UTC
Statement:

This issue did not affect the version of the stunnel package as shipped with Red Hat Enterprise Linux 5.


Note You need to log in before you can comment on or make changes to this bug.