MGASA-2015-0144
Dashboard / Vulnerabilities / MGASA-2015-0144
Summary: Updated socat packages fix CVE-2015-1379
Details: Updated socat package fixes security vulnerability: In socat before 2.0.0-b8, signal handler implementations are not async-signal-safe and can cause crash or freeze of socat processes. Mostly this issue occurs when socat is in listening mode with fork option and a couple of child processes terminate at the same time (CVE-2015-1379).
References: https://advisories.mageia.org/MGASA-2015-0144.html, https://bugs.mageia.org/show_bug.cgi?id=15131, http://openwall.com/lists/oss-security/2015/04/06/4
Affected packages
Package
Name: socat
Purl: pkg:rpm/mageia/socat?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -2.0.0-0.b8.1.mga4
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
