Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Santiago Zanella-Beguelin

Pesquisador deMicrosoft Vulnerability Research (MSVR)
#47553de 53,639
5.3CVSS total
Vulnerabilidades · 1
PT-2017-8013
5.3
2016-02-05
Openssl · Socat · CVE-2016-2217
**Name of the Vulnerable Software and Affected Versions** Socat versions 1.7.3.0 through 2.0.0-b8 **Description** The issue lies in the OpenSSL address implementation, which does not utilize a prime number for the Diffie-Hellman (DH) key exchange. This oversight makes it easier for remote attackers to obtain the shared secret, potentially compromising the security of the connection. **Recommendations** For Socat version 1.7.3.0, update to a version that uses a prime number for the DH key exchange to prevent remote attackers from obtaining the shared secret. For Socat version 2.0.0-b8, update to a version that uses a prime number for the DH key exchange to prevent remote attackers from obtaining the shared secret.