A potential remote root vulnerability has been found for stunnel versions 4.40 and 4.41 which might possibly affect the earlier version in use on our Blocks Load Balancer product for SSL tunnel termination. As such, we will be rolling out a security update for this software this afternoon. As part of this update we will need to restart the stunnel daemons listening for any load balanced services using SSL offloading (which includes the vast majority of load balanced services using the https:// protocol). No functionality changes are expected as a result of this upgrade. However, restarting the service means that each SSL-offloaded load balanced service will experience a < 1 second “hiccup” as the stunnel service is restarted. Please contact support@bluebox.net if you have questions about this.
stunnel update on Blocks Load Balancers