Input validation error in socat - CVE-2013-3571

 

Input validation error in socat - CVE-2013-3571

Published: May 8, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41710
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-3571
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

socat 1.2.0.0 before 1.7.2.2 and 2.0.0-b1 before 2.0.0-b6, when used for a listen type address and the fork option is enabled, allows remote attackers to cause a denial of service (file descriptor consumption) via multiple request that are refused based on the (1) sourceport, (2) lowport, (3) range, or (4) tcpwrap restrictions.


Affected software

socat
Amazon Linux AMI
Fedora
socat (Alpine package)
socat

How to mitigate CVE-2013-3571

Install update from vendor's website.

socat (Alpine package) - update to 1.7.2.2-r0
socat - addressed in versions 1.7.2.2-1.el5, 1.7.2.2-1.el6

External References

Related Security Bulletins