Socat Remote Format String Vulnerability
BID:11505
Info
Socat Remote Format String Vulnerability
| Bugtraq ID: | 11505 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2004 12:00AM |
| Updated: | Oct 22 2004 12:00AM |
| Credit: | CoKi of No System Group disclosed this vulnerability. |
| Vulnerable: |
socat socat 1.4 .0.2 socat socat 1.4 .0.1 socat socat 1.4 .0.0 socat socat 1.3 .x socat socat 1.2 .x socat socat 1.1 .x socat socat 1.0 .x |
| Not Vulnerable: |
socat socat 1.4 .0.3 |
Discussion
Socat Remote Format String Vulnerability
It is reported that socat is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.
This vulnerability reportedly allows remote attackers to execute arbitrary code in the context of the socat process.
Versions prior to 1.4.0.3 are reported to be vulnerable.
It is reported that socat is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.
This vulnerability reportedly allows remote attackers to execute arbitrary code in the context of the socat process.
Versions prior to 1.4.0.3 are reported to be vulnerable.
Exploit / POC
Socat Remote Format String Vulnerability
An proof-of-concept exploit has been provided:
An proof-of-concept exploit has been provided:
Solution / Fix
Socat Remote Format String Vulnerability
Solution:
The vendor has released a new version of the package to address this issue:
Gentoo has released an advisory (GLSA 200410-26) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following actions to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=net-misc/socat-1.4.0.3"
socat socat 1.0 .x
socat socat 1.1 .x
socat socat 1.2 .x
socat socat 1.3 .x
socat socat 1.4 .0.0
socat socat 1.4 .0.1
socat socat 1.4 .0.2
Solution:
The vendor has released a new version of the package to address this issue:
Gentoo has released an advisory (GLSA 200410-26) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following actions to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=net-misc/socat-1.4.0.3"
socat socat 1.0 .x
-
socat socat-1.4.0.3.tar.gz
http://www.dest-unreach.org/socat/download/socat-1.4.0.3.tar.gz
socat socat 1.1 .x
-
socat socat-1.4.0.3.tar.gz
http://www.dest-unreach.org/socat/download/socat-1.4.0.3.tar.gz
socat socat 1.2 .x
-
socat socat-1.4.0.3.tar.gz
http://www.dest-unreach.org/socat/download/socat-1.4.0.3.tar.gz
socat socat 1.3 .x
-
socat socat-1.4.0.3.tar.gz
http://www.dest-unreach.org/socat/download/socat-1.4.0.3.tar.gz
socat socat 1.4 .0.0
-
socat socat-1.4.0.3.tar.gz
http://www.dest-unreach.org/socat/download/socat-1.4.0.3.tar.gz
socat socat 1.4 .0.1
-
socat socat-1.4.0.3.tar.gz
http://www.dest-unreach.org/socat/download/socat-1.4.0.3.tar.gz
socat socat 1.4 .0.2
-
socat socat-1.4.0.3.tar.gz
http://www.dest-unreach.org/socat/download/socat-1.4.0.3.tar.gz
References
Socat Remote Format String Vulnerability
References:
References:
- Socat (No System Group)
- socat Home Page (socat)
- socat Security Advisory 1 (socat)