CVE-2014-0016
Summary
| CVE | CVE-2014-0016 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-03-24 16:31:08 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Stunnel | Stunnel | 0.1 | All | All | All |
| Application | Stunnel | Stunnel | 1.0 | All | All | All |
| Application | Stunnel | Stunnel | 1.1 | All | All | All |
| Application | Stunnel | Stunnel | 1.2 | All | All | All |
| Application | Stunnel | Stunnel | 1.3 | All | All | All |
| Application | Stunnel | Stunnel | 1.4 | All | All | All |
| Application | Stunnel | Stunnel | 1.5 | All | All | All |
| Application | Stunnel | Stunnel | 1.6 | All | All | All |
| Application | Stunnel | Stunnel | 2.0 | All | All | All |
| Application | Stunnel | Stunnel | 2.1 | All | All | All |
| Application | Stunnel | Stunnel | 3.0 | All | All | All |
| Application | Stunnel | Stunnel | 3.0 | b1 | All | All |
| Application | Stunnel | Stunnel | 3.0 | b2 | All | All |
| Application | Stunnel | Stunnel | 3.0 | b3 | All | All |
| Application | Stunnel | Stunnel | 3.0 | b4 | All | All |
| Application | Stunnel | Stunnel | 3.0 | b5 | All | All |
| Application | Stunnel | Stunnel | 3.0 | b6 | All | All |
| Application | Stunnel | Stunnel | 3.0 | b7 | All | All |
| Application | Stunnel | Stunnel | 3.1 | All | All | All |
| Application | Stunnel | Stunnel | 3.10 | All | All | All |
| Application | Stunnel | Stunnel | 3.11 | All | All | All |
| Application | Stunnel | Stunnel | 3.12 | All | All | All |
| Application | Stunnel | Stunnel | 3.13 | All | All | All |
| Application | Stunnel | Stunnel | 3.14 | All | All | All |
| Application | Stunnel | Stunnel | 3.15 | All | All | All |
| Application | Stunnel | Stunnel | 3.16 | All | All | All |
| Application | Stunnel | Stunnel | 3.17 | All | All | All |
| Application | Stunnel | Stunnel | 3.18 | All | All | All |
| Application | Stunnel | Stunnel | 3.19 | All | All | All |
| Application | Stunnel | Stunnel | 3.2 | All | All | All |
| Application | Stunnel | Stunnel | 3.20 | All | All | All |
| Application | Stunnel | Stunnel | 3.21 | All | All | All |
| Application | Stunnel | Stunnel | 3.21a | All | All | All |
| Application | Stunnel | Stunnel | 3.21b | All | All | All |
| Application | Stunnel | Stunnel | 3.21c | All | All | All |
| Application | Stunnel | Stunnel | 3.22 | All | All | All |
| Application | Stunnel | Stunnel | 3.23 | All | All | All |
| Application | Stunnel | Stunnel | 3.24 | All | All | All |
| Application | Stunnel | Stunnel | 3.25 | All | All | All |
| Application | Stunnel | Stunnel | 3.26 | All | All | All |
| Application | Stunnel | Stunnel | 3.3 | All | All | All |
| Application | Stunnel | Stunnel | 3.4a | All | All | All |
| Application | Stunnel | Stunnel | 3.5 | All | All | All |
| Application | Stunnel | Stunnel | 3.6 | All | All | All |
| Application | Stunnel | Stunnel | 3.7 | All | All | All |
| Application | Stunnel | Stunnel | 3.8 | All | All | All |
| Application | Stunnel | Stunnel | 3.8 | p1 | All | All |
| Application | Stunnel | Stunnel | 3.8 | p2 | All | All |
| Application | Stunnel | Stunnel | 3.8 | p3 | All | All |
| Application | Stunnel | Stunnel | 3.8 | p4 | All | All |
| Application | Stunnel | Stunnel | 3.8p1 | All | All | All |
| Application | Stunnel | Stunnel | 3.8p2 | All | All | All |
| Application | Stunnel | Stunnel | 3.8p3 | All | All | All |
| Application | Stunnel | Stunnel | 3.8p4 | All | All | All |
| Application | Stunnel | Stunnel | 3.9 | All | All | All |
| Application | Stunnel | Stunnel | 4.0 | All | All | All |
| Application | Stunnel | Stunnel | 4.00 | All | All | All |
| Application | Stunnel | Stunnel | 4.01 | All | All | All |
| Application | Stunnel | Stunnel | 4.02 | All | All | All |
| Application | Stunnel | Stunnel | 4.03 | All | All | All |
| Application | Stunnel | Stunnel | 4.04 | All | All | All |
| Application | Stunnel | Stunnel | 4.05 | All | All | All |
| Application | Stunnel | Stunnel | 4.06 | All | All | All |
| Application | Stunnel | Stunnel | 4.07 | All | All | All |
| Application | Stunnel | Stunnel | 4.08 | All | All | All |
| Application | Stunnel | Stunnel | 4.09 | All | All | All |
| Application | Stunnel | Stunnel | 4.10 | All | All | All |
| Application | Stunnel | Stunnel | 4.11 | All | All | All |
| Application | Stunnel | Stunnel | 4.12 | All | All | All |
| Application | Stunnel | Stunnel | 4.13 | All | All | All |
| Application | Stunnel | Stunnel | 4.14 | All | All | All |
| Application | Stunnel | Stunnel | 4.15 | All | All | All |
| Application | Stunnel | Stunnel | 4.16 | All | All | All |
| Application | Stunnel | Stunnel | 4.17 | All | All | All |
| Application | Stunnel | Stunnel | 4.18 | All | All | All |
| Application | Stunnel | Stunnel | 4.19 | All | All | All |
| Application | Stunnel | Stunnel | 4.20 | All | All | All |
| Application | Stunnel | Stunnel | 4.21 | All | All | All |
| Application | Stunnel | Stunnel | 4.22 | All | All | All |
| Application | Stunnel | Stunnel | 4.23 | All | All | All |
| Application | Stunnel | Stunnel | 4.24 | All | All | All |
| Application | Stunnel | Stunnel | 4.25 | All | All | All |
| Application | Stunnel | Stunnel | 4.26 | All | All | All |
| Application | Stunnel | Stunnel | 4.27 | All | All | All |
| Application | Stunnel | Stunnel | 4.28 | All | All | All |
| Application | Stunnel | Stunnel | 4.29 | All | All | All |
| Application | Stunnel | Stunnel | 4.30 | All | All | All |
| Application | Stunnel | Stunnel | 4.31 | All | All | All |
| Application | Stunnel | Stunnel | 4.32 | All | All | All |
| Application | Stunnel | Stunnel | 4.33 | All | All | All |
| Application | Stunnel | Stunnel | 4.34 | All | All | All |
| Application | Stunnel | Stunnel | 4.35 | All | All | All |
| Application | Stunnel | Stunnel | 4.36 | All | All | All |
| Application | Stunnel | Stunnel | 4.37 | All | All | All |
| Application | Stunnel | Stunnel | 4.38 | All | All | All |
| Application | Stunnel | Stunnel | 4.39 | All | All | All |
| Application | Stunnel | Stunnel | 4.40 | All | All | All |
| Application | Stunnel | Stunnel | 4.41 | All | All | All |
| Application | Stunnel | Stunnel | 4.42 | All | All | All |
| Application | Stunnel | Stunnel | 4.43 | All | All | All |
| Application | Stunnel | Stunnel | 4.44 | All | All | All |
| Application | Stunnel | Stunnel | 4.45 | All | All | All |
| Application | Stunnel | Stunnel | 4.46 | All | All | All |
| Application | Stunnel | Stunnel | 4.47 | All | All | All |
| Application | Stunnel | Stunnel | 4.48 | All | All | All |
| Application | Stunnel | Stunnel | 4.49 | All | All | All |
| Application | Stunnel | Stunnel | 4.50 | All | All | All |
| Application | Stunnel | Stunnel | 4.51 | All | All | All |
| Application | Stunnel | Stunnel | 4.52 | All | All | All |
| Application | Stunnel | Stunnel | 4.53 | All | All | All |
| Application | Stunnel | Stunnel | 4.54 | All | All | All |
| Application | Stunnel | Stunnel | 4.55 | All | All | All |
| Application | Stunnel | Stunnel | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| stunnel: ChangeLog | af854a3a-2127-422b-91ae-364da2661108 | www.stunnel.org | Release Notes, Vendor Advisory |
| Attachment 870826 Details for Bug 1072180 – proposed patch | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| Bug 1072180 – CVE-2014-0016 stunnel: Improper initialization of PRNG after fork() | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Third Party Advisory, VDB Entry |
| oss-security - libssh and stunnel PRNG flaws | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| Stunnel CVE-2014-0016 PRNG Initialization Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.