{"id":"CVE-2015-3644","details":"Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers to bypass authentication.","modified":"2026-04-16T06:22:07.828351123Z","published":"2015-05-14T00:59:06Z","related":["SUSE-SU-2015:1062-1","openSUSE-SU-2024:12196-1"],"references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2015/dsa-3299"},{"type":"ADVISORY","url":"https://www.stunnel.org/CVE-2015-3644.html"},{"type":"FIX","url":"https://www.stunnel.org/CVE-2015-3644.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/74659"},{"type":"WEB","url":"http://www.securitytracker.com/id/1032324"}],"schema_version":"1.7.5"}