CLSA-2023-1689701258
Dashboard / Vulnerabilities / CLSA-2023-1689701258
Summary: Fix CVE(s): CVE-2021-20230
Details: * SECURITY UPDATE: Attacker bypasses redirection using unauthorized CA-signed certificate. - debian/patches/CVE-2021-20230.patch: Patch enhancing certificate verification process to prevent unauthorized redirection with CA-signed certificates by refining session data checks. - CVE-2021-20230 * Fix tests: - debian/patches/renew-cert-script.patch: Add script that re-generate expired test certs. * Repacked orig source tarball with renewed certs. * Removed no longer required patch, that mute tests with expired certificates.
Affected packages
Package
Name: stunnel4
Purl: pkg:deb/tuxcare/stunnel4?distro=ubuntu-18.04
Affected ranges
Type: ECOSYSTEM
Events:
