socat up to version 1.4.0.2 contains a syslog() based format string
vulnerability. Further investigation showed that this vulnerability could,
under some circumstances, lead to local or remote execution of arbitrary
code with the privileges of the socat process. See this socat
advisory for additional details.