Input validation error in socat - CVE-2013-3571
Published: May 8, 2014 / Updated: August 10, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
socat 1.2.0.0 before 1.7.2.2 and 2.0.0-b1 before 2.0.0-b6, when used for a listen type address and the fork option is enabled, allows remote attackers to cause a denial of service (file descriptor consumption) via multiple request that are refused based on the (1) sourceport, (2) lowport, (3) range, or (4) tcpwrap restrictions.
Affected software
Amazon Linux AMI
Fedora
socat (Alpine package)
socat
How to mitigate CVE-2013-3571
socat - addressed in versions 1.7.2.2-1.el5, 1.7.2.2-1.el6