CVE-2015-3644 REJECTED

Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers to bypass authentication.

EPSS 0.25% · 47.9th percentile

Risk Scores

EPSS Score
0.25%
47.9th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSstunnel40

Timeline

References

Open in Interactive Console →