FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

socat -- diffie hellman parameter was not prime

Affected packages
1.7.2.5 <= socat < 1.7.3.1

Details

VuXML ID a52a7172-c92e-11e5-96d6-14dae9d210b8
Discovery 2016-02-01
Entry 2016-02-01

socat reports:

In the OpenSSL address implementation the hard coded 1024 bit DH p parameter was not prime. The effective cryptographic strength of a key exchange using these parameters was weaker than the one one could get by using a prime p. Moreover, since there is no indication of how these parameters were chosen, the existence of a trapdoor that makes possible for an eavesdropper to recover the shared secret from a key exchange that uses them cannot be ruled out.

References

URL http://www.dest-unreach.org/socat/contrib/socat-secadv7.html