PT-2012-2410 · Socat+1 · Socat+1

Johan Thillemann

·

Publicado

2012-06-21

·

Atualizado

2014-05-10

·

CVE-2012-0219

CVSS v2.0

6.2

Média

VetorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions socat versions 1.4.0.0 through 1.7.2.0 socat versions 2.0.0-b1 through 2.0.0-b4
Description A heap-based buffer overflow issue exists in the xioscan readline function, located in the xio-readline.c file. This allows local users to execute arbitrary code via the READLINE address.
Recommendations For socat versions 1.4.0.0 through 1.7.2.0, update to a version outside of this range to resolve the issue. For socat versions 2.0.0-b1 through 2.0.0-b4, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the xioscan readline function in the xio-readline.c file until a patch is available.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-0219

Produtos afetados

Suse
Socat