Back
CVE-2001-0060
Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.
Published: Feb 12, 2001
Modified: Apr 16, 2026
CVSS Metrics
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| stunnel | stunnel | 3.3 |
| stunnel | stunnel | 3.4a |
| stunnel | stunnel | 3.7 |
| stunnel | stunnel | 3.8 |
References (14)
- http://archives.neohapsis.com/archives/bugtraq/2000-12/0337.html Patch, Vendor Advisory
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000363
- http://www.debian.org/security/2001/dsa-009
- http://www.redhat.com/support/errata/RHSA-2000-129.html
- http://www.securityfocus.com/archive/1/151719 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/2128 Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5807
- http://archives.neohapsis.com/archives/bugtraq/2000-12/0337.html Patch, Vendor Advisory
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000363
- http://www.debian.org/security/2001/dsa-009
- http://www.redhat.com/support/errata/RHSA-2000-129.html
- http://www.securityfocus.com/archive/1/151719 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/2128 Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5807
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
2.77%
Top 16% most likely to be exploited
Threat Score
40.8 / 100
Data Sources
NVD
EPSS