MEDIUM · 4.3

CVE-2014-0016

stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to us...

Vulnerability Description

stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
StunnelStunnel<= 4.56

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-0016?

CVE-2014-0016 is a vulnerability with a CVSS score of 4.3 (MEDIUM). stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to us...

How severe is CVE-2014-0016?

CVE-2014-0016 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-0016?

Check the references section above for vendor advisories and patch information. Affected products include: Stunnel Stunnel.