Back

CVE-2001-0060

Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.

Published: Feb 12, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
stunnel stunnel 3.3
stunnel stunnel 3.4a
stunnel stunnel 3.7
stunnel stunnel 3.8

GitHub Security Advisory GHSA-cpcw-2gx9-xcwx

Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 2.77%

Top 15% most likely to be exploited

Threat Score 40.8 / 100

Data Sources

NVD EPSS GitHub