FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-0219

This CVE name corresponds to:

Entered Topic
2012-05-14 socat -- Heap-based buffer overflow

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-0219
Phase Assigned(20111214)

Description

Heap-based buffer overflow in the xioscan_readline function in xio-readline.c in socat 1.4.0.0 through 1.7.2.0 and 2.0.0-b1 through 2.0.0-b4 allows local users to execute arbitrary code via the READLINE address.

References

Source Reference
MLIST [oss-security] 20120514 socat security advisory
CONFIRM http://www.dest-unreach.org/socat/contrib/socat-secadv3.html
FEDORA FEDORA-2012-8274
FEDORA FEDORA-2012-8328
GENTOO GLSA-201208-01
MANDRIVA MDVSA-2013:169
SUSE openSUSE-SU-2012:0809
BID 53510
OSVDB 81969
SECTRACK 1027064
SECUNIA 49105
SECUNIA 49746