Input validation error in socat - CVE-2015-1379
Published: June 9, 2017 / Updated: August 3, 2020
Vulnerability identifier: #VU33085
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-1379
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The signal handler implementations in socat before 1.7.3.0 and 2.0.0-b8 allow remote attackers to cause a denial of service (process freeze or crash).
Affected software
socat
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
socat (Alpine package)
socat-debuginfo
socat-debugsource
socat
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
socat (Alpine package)
socat-debuginfo
socat-debugsource
socat
How to mitigate CVE-2015-1379
Install update from vendor's website.
socat - update to 1.7.3.0
socat (Alpine package) - update to 1.7.3.0-r0
socat-debuginfo - update to 1.7.2.4-4.6.1
socat-debugsource - update to 1.7.2.4-4.6.1
socat - update to 1.7.2.4-4.6.1
socat (Alpine package) - update to 1.7.3.0-r0
socat-debuginfo - update to 1.7.2.4-4.6.1
socat-debugsource - update to 1.7.2.4-4.6.1
socat - update to 1.7.2.4-4.6.1