CVE-2014-0016 describes a vulnerability in stunnel versions prior to 5.00 when configured for fork threading. This flaw prevents proper updating of the OpenSSL pseudo-random number generator (PRNG) state, leading to subsequent child processes reusing the same entropy pool. This medium-complexity vulnerability (CVSS 4.3) allows remote attackers to potentially compromise private keys for EC (ECDSA) or DSA certificates, resulting in a partial confidentiality impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.56CPE matchmatch criteria | cpe:2.3:a:stunnel:stunnel:*:*:*:*:*:*:*:* | ||
0.1CPE matchmatch criteria | cpe:2.3:a:stunnel:stunnel:0.1:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:stunnel:stunnel:1.0:*:*:*:*:*:*:* | ||
1.1CPE matchmatch criteria | cpe:2.3:a:stunnel:stunnel:1.1:*:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:a:stunnel:stunnel:1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.