Input validation error in socat - CVE-2015-1379

 

Input validation error in socat - CVE-2015-1379

Published: June 9, 2017 / Updated: August 3, 2020


Vulnerability identifier: #VU33085
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-1379
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The signal handler implementations in socat before 1.7.3.0 and 2.0.0-b8 allow remote attackers to cause a denial of service (process freeze or crash).


Affected software

socat
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
socat (Alpine package)
socat-debuginfo
socat-debugsource
socat

How to mitigate CVE-2015-1379

Install update from vendor's website.

socat - update to 1.7.3.0
socat (Alpine package) - update to 1.7.3.0-r0
socat-debuginfo - update to 1.7.2.4-4.6.1
socat-debugsource - update to 1.7.2.4-4.6.1
socat - update to 1.7.2.4-4.6.1

External References

Related Security Bulletins