Back to Database
Status published
Critical
CVE-2011-2940
stunnel 4.40 and 4.41 might allow remote attackers to execute...
Vulnerability Description
stunnel 4.40 and 4.41 might allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-2940
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.openwall.com/lists/oss-security/2011/08/19/6
- http://securitytracker.com/id?1025959
- http://www.openwall.com/lists/oss-security/2011/08/19/18
- https://bugzilla.redhat.com/show_bug.cgi?id=732068
- http://stunnel.org/?page=sdf_ChangeLog
- http://www.securityfocus.com/bid/49254
- http://www.stunnel.org/pipermail/stunnel-announce/2011-August/000059.html
- http://www.osvdb.org/74600
- http://secunia.com/advisories/45705
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69318
More from stunnel
View All →CVE-2015-3644
Stunnel 5.00 through 5.13, when using the redirect option, does...
Medium
5.8
CVE-2014-0016
stunnel before 5.00, when using fork threading, does not properly...
Medium
4.3
CVE-2013-1762
stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM...
Medium
6.6
CVE-2008-2420
The OCSP functionality in stunnel before 4.24 does not properly...
Medium
6.8
CVE-2008-2400
Unspecified vulnerability in stunnel before 4.23, when running as a...
High
7.2
Affected Vendor
stunnel
View all reports →Affected Software
stunnel
Vulnerable Versions:
4.40, 4.41
Timeline
Official Publish:
August 25th, 2011
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.