socat 'nestlex()' Command Line Argument Buffer Overflow Vulnerability
BID:42112
Info
socat 'nestlex()' Command Line Argument Buffer Overflow Vulnerability
| Bugtraq ID: | 42112 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-2799 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2010 12:00AM |
| Updated: | Apr 13 2015 09:30PM |
| Credit: | Felix Gröbert |
| Vulnerable: |
socat socat 2.0.0-b3 socat socat 2.0.0-b2 socat socat 2.0.0-b1 socat socat 1.7.1.2 socat socat 1.7.1.1 socat socat 1.7.1.0 socat socat 1.7.0.1 socat socat 1.7.0.0 socat socat 1.6.0.1 socat socat 1.6.0.0 socat socat 1.5.0.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 |
| Not Vulnerable: |
socat socat 2.0.0-b4 socat socat 1.7.1.3 |
Discussion
socat 'nestlex()' Command Line Argument Buffer Overflow Vulnerability
socat is prone to a remote buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
socat versions 1.5.0.0 through 1.7.1.2 and 2.0.0-b1 through 2.0.0-b3 are vulnerable.
socat is prone to a remote buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
socat versions 1.5.0.0 through 1.7.1.2 and 2.0.0-b1 through 2.0.0-b3 are vulnerable.
Exploit / POC
socat 'nestlex()' Command Line Argument Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
socat 'nestlex()' Command Line Argument Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
MandrakeSoft Enterprise Server 5 x86_64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
-
Mandriva socat-1.6.0.0-4.1mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva socat-1.6.0.0-4.1mdvmes5.1.x86_64.rpm
http://www.mandriva.com/en/download/
References
socat 'nestlex()' Command Line Argument Buffer Overflow Vulnerability
References:
References:
- Socat security advisory 2 (socat)