Stunnel CVE-2014-0016 PRNG Initialization Weakness
BID:65964
Info
Stunnel CVE-2014-0016 PRNG Initialization Weakness
| Bugtraq ID: | 65964 |
| Class: | Design Error |
| CVE: |
CVE-2014-0016 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2014 12:00AM |
| Updated: | Feb 02 2017 06:00AM |
| Credit: | Aris Adamantiadis |
| Vulnerable: |
Stunnel Stunnel 4.0 4 Stunnel Stunnel 4.0 3 Stunnel Stunnel 4.0 2 Stunnel Stunnel 4.0 1 Stunnel Stunnel 4.0 0 Stunnel Stunnel 3.26 Stunnel Stunnel 3.25 Stunnel Stunnel 3.24 Stunnel Stunnel 3.22 Stunnel Stunnel 3.21 c Stunnel Stunnel 3.21 b Stunnel Stunnel 3.21 a Stunnel Stunnel 3.21 Stunnel Stunnel 3.19 Stunnel Stunnel 3.18 Stunnel Stunnel 3.17 Stunnel Stunnel 3.16 Stunnel Stunnel 3.15 Stunnel Stunnel 3.14 Stunnel Stunnel 3.13 Stunnel Stunnel 3.12 Stunnel Stunnel 3.11 Stunnel Stunnel 3.9 Stunnel Stunnel 3.8 Stunnel Stunnel 3.7 Stunnel Stunnel 3.4 a Stunnel Stunnel 3.3 Stunnel Stunnel 4.56 Stunnel Stunnel 4.55 Stunnel Stunnel 4.54 Stunnel Stunnel 4.53 Stunnel Stunnel 4.52 Stunnel Stunnel 4.42 Stunnel Stunnel 4.41 Stunnel Stunnel 4.40 Stunnel Stunnel 4.35 Stunnel Stunnel 4.34 Stunnel Stunnel 4.33 Stunnel Stunnel 4.32 Stunnel Stunnel 4.31 Stunnel Stunnel 4.30 Stunnel Stunnel 4.24 Stunnel Stunnel 4.23 Stunnel Stunnel 4.22 Stunnel Stunnel 4.21 Stunnel Stunnel 3.20 Stunnel Stunnel 3.10 Stunnel Stunnel 3.0 Stunnel Stunnel 2.0 Oracle Solaris 11.3 Gentoo Linux |
| Not Vulnerable: |
Stunnel Stunnel 5.14 Stunnel Stunnel 5.13 Stunnel Stunnel 5.12 Stunnel Stunnel 5.11 Stunnel Stunnel 5.10 Stunnel Stunnel 5.09 Stunnel Stunnel 5.08 Stunnel Stunnel 5.07 Stunnel Stunnel 5.06 Stunnel Stunnel 5.05 Stunnel Stunnel 5.04 Stunnel Stunnel 5.03 Stunnel Stunnel 5.02 Stunnel Stunnel 5.01 Stunnel Stunnel 5.00 Stunnel Stunnel 4.57 |
Discussion
Stunnel CVE-2014-0016 PRNG Initialization Weakness
Stunnel is prone to a security weakness because it fails to properly Initialization PRNG.
An attacker can exploit this weakness to predict random number values that can aid in further attacks.
Stunnel 2.00 through 4.56 are vulnerable.
Stunnel is prone to a security weakness because it fails to properly Initialization PRNG.
An attacker can exploit this weakness to predict random number values that can aid in further attacks.
Stunnel 2.00 through 4.56 are vulnerable.
Exploit / POC
Stunnel CVE-2014-0016 PRNG Initialization Weakness
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Stunnel CVE-2014-0016 PRNG Initialization Weakness
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Stunnel CVE-2014-0016 PRNG Initialization Weakness
References:
References:
- Bug 1072180 - (CVE-2014-0016) CVE-2014-0016 stunnel: Improper initialization of (Red Hat)
- Stunnel Homepage (Stunnel)
- stunnel: ChangeLog (Stunnel)
- stunnel: CVE-2014-0016 (Stunnel)
- Oracle Solaris Third Party Bulletin - January 2017 (Oracle)