{"schema_version":"1.7.5","id":"CVE-2013-1762","published":"2013-03-08T18:55:01Z","modified":"2026-04-10T03:42:42.884269Z","related":["openSUSE-SU-2024:10289-1"],"details":"stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.","references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2013-0714.html"},{"type":"ADVISORY","url":"http://www.debian.org/security/2013/dsa-2664"},{"type":"ADVISORY","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2013:130"},{"type":"ADVISORY","url":"https://www.stunnel.org/CVE-2013-1762.html"},{"type":"WEB","url":"https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0097"}]}