CVE-2014-0019

Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line.
Severity
UNKNOWN
AV:L/AC:M/Au:N/C:N/I:N/A:P
Atk. Vector
LOCAL
Atk. Complexity
MEDIUM
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
VendorProductVersion
dest-unreachsocat
2.0.0
dest-unreachsocat
2.0.0
dest-unreachsocat
2.0.0
dest-unreachsocat
2.0.0
dest-unreachsocat
2.0.0
dest-unreachsocat
2.0.0
opensuseopensuse
13.1
dest-unreachsocat
1.3.0.0
dest-unreachsocat
1.3.0.1
dest-unreachsocat
1.3.1.0
dest-unreachsocat
1.3.2.0
dest-unreachsocat
1.3.2.1
dest-unreachsocat
1.3.2.2
dest-unreachsocat
1.4.0.0
dest-unreachsocat
1.4.0.1
dest-unreachsocat
1.4.0.2
dest-unreachsocat
1.4.0.3
dest-unreachsocat
1.4.1.0
dest-unreachsocat
1.4.2.0
dest-unreachsocat
1.4.3.0
dest-unreachsocat
1.4.3.1
dest-unreachsocat
1.5.0.0
dest-unreachsocat
1.6.0.0
dest-unreachsocat
1.6.0.1
dest-unreachsocat
1.7.0.0
dest-unreachsocat
1.7.0.1
dest-unreachsocat
1.7.1.0
dest-unreachsocat
1.7.1.1
dest-unreachsocat
1.7.1.2
dest-unreachsocat
1.7.1.3
dest-unreachsocat
1.7.2.0
dest-unreachsocat
1.7.2.1
dest-unreachsocat
1.7.2.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
socat
bullseye
1.7.4.1-3
fixed
squeeze
no-dsa
wheezy
no-dsa
bookworm
1.7.4.4-2
fixed
sid
1.8.0.1-2
fixed
trixie
1.8.0.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
socat
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
not-affected
saucy
ignored
quantal
ignored
precise
ignored
lucid
ignored