socat PROXY-CONNECT Address Stack Buffer Overflow Vulnerability
BID:65201
Info
socat PROXY-CONNECT Address Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 65201 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-0019 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2014 12:00AM |
| Updated: | Apr 16 2015 06:15PM |
| Credit: | Florian Weimer of Red Hat |
| Vulnerable: |
socat socat 2.0.0-b5 socat socat 2.0.0-b4 socat socat 2.0.0-b3 socat socat 2.0.0-b2 socat socat 2.0.0-b1 socat socat 1.7.2.1 socat socat 1.7.2.0 socat socat 1.7.1.3 socat socat 1.7.1.2 socat socat 1.7.1.1 socat socat 1.7.1.0 socat socat 1.7.0.1 socat socat 1.7.0.0 socat socat 1.6.0.1 socat socat 1.6.0.0 socat socat 1.5.0.0 |
| Not Vulnerable: | |
Discussion
socat PROXY-CONNECT Address Stack Buffer Overflow Vulnerability
socat is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary-checks on user-supplied input.
An attacker can exploit this issue to cause denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible; this has not been confirmed.
socat versions 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 are vulnerable.
socat is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary-checks on user-supplied input.
An attacker can exploit this issue to cause denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible; this has not been confirmed.
socat versions 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 are vulnerable.
Exploit / POC
socat PROXY-CONNECT Address Stack Buffer Overflow Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
socat PROXY-CONNECT Address Stack Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.