1.9 Low
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:L/AC:M/Au:N/C:N/I:N/A:P
6.4 Medium
AI Score
Confidence
High
0.0004 Low
EPSS
Percentile
5.1%
Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line.
CPE | Name | Operator | Version |
---|---|---|---|
dest-unreach:socat | dest-unreach socat | eq | 2.0.0 |
lists.fedoraproject.org/pipermail/package-announce/2014-February/128190.html
lists.fedoraproject.org/pipermail/package-announce/2014-February/128229.html
lists.opensuse.org/opensuse-updates/2015-04/msg00043.html
osvdb.org/102612
seclists.org/oss-sec/2014/q1/159
www.dest-unreach.org/socat
www.dest-unreach.org/socat/contrib/socat-secadv5.txt
www.mandriva.com/security/advisories?name=MDVSA-2014:033
www.securityfocus.com/bid/65201