Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers to bypass authentication.
https://www.stunnel.org/CVE-2015-3644.html
http://www.securitytracker.com/id/1032324