FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2014-0019

This CVE name corresponds to:

Entered Topic
2014-01-29 socat -- buffer overflow with data from command line

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2014-0019
Phase Assigned(20131203)

Description

Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line.

References

Source Reference
MLIST [oss-security] 20140128 Socat security advisory 5 - PROXY-CONNECT address overflow
MISC http://www.dest-unreach.org/socat/contrib/socat-secadv5.txt
CONFIRM http://www.dest-unreach.org/socat
FEDORA FEDORA-2014-1795
FEDORA FEDORA-2014-1811
MANDRIVA MDVSA-2014:033
SUSE openSUSE-SU-2015:0760
BID 65201
OSVDB 102612