CNCVE编号:CNCVE-20010060 CVE编号:CVE-2001-0060 安全级别:高 漏洞中文描述: stunnel 3.8及其早期版本中的格式化字符串漏洞允许攻击者通过一个畸形的“ident”用户名来执行任意命令. 漏洞英文描述: Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username. 漏洞参考: BID:2128 XF:stunnel-format-logfile BUGTRAQ:20001209 Trustix Security Advisory - stunnel BUGTRAQ:20001218 Stunnel format bug REDHAT:RHSA-2000:129-02 CONECTIVA:CLA-2000:363 DEBIAN:20001225 DSA-009-1 stunnel: insecure file handling, format string bug 系统类型:其他 漏洞类型:输入有效性检查错误