Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2002-0002

6 documents6 sources
Severity
7.5HIGH
EPSS
15.6%
top 5.30%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 31
Latest updateApr 30

Description

Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages4 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8qj7-vx74-c666: Format string vulnerability in stunnel before 32022-04-30
CVEList
CVE-2002-0002: Format string vulnerability in stunnel before 32002-06-25

💥Exploits & PoCs

1
Exploit-DB
STunnel 3.x - Client Negotiation Protocol Format String2001-12-22

📋Vendor Advisories

1
Red Hat
security flaw2001-12-18

💬Community

1
Bugzilla
CVE-2002-0002 security flaw2018-08-16
CVE-2002-0002 (HIGH CVSS 7.5) | Format string vulnerability in stun | cvebase.io