USN-6901-1: stunnel vulnerability
18 July 2024
stunnel could allow unintended access to network services.
Releases
Packages
- stunnel4 - Universal SSL tunnel for network daemons
Details
It was discovered that stunnel did not properly validate client
certificates when configured to use both the redirect and verifyChain
options. A remote attacker could potentially use this issue to obtain
sensitive information by accessing the tunneled service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
Ubuntu 18.04
-
stunnel4
-
3:5.44-1ubuntu3+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.