stunnel 4.46 < 5.34 Improper Level 4 Peer Certificate Validation Security Bypass
Critical Nessus Plugin ID 92557
SynopsisAn application installed on the remote host is affected by a security bypass vulnerability.
DescriptionThe version of stunnel installed on the remote host is 4.46 or later but prior to 5.34. It is, therefore, affected by a security bypass vulnerability related to the validation of level 4 peer certificates.
An unauthenticated, remote attacker can exploit this to have an impact on confidentiality, integrity, and/or availability. No other details are available.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
SolutionUpgrade to stunnel version 5.34 or later.