LWN.net Logo

socat: format string vulnerability

Package(s):socat CVE #(s):
Created:October 25, 2004 Updated:October 27, 2004
Description: socat up to version 1.4.0.2 contains a syslog() based format string vulnerability. Further investigation showed that this vulnerability could, under some circumstances, lead to local or remote execution of arbitrary code with the privileges of the socat process. See this socat advisory for additional details.
Alerts:
Gentoo 200410-26 2004-10-25

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds