SUSE-SU-2016:0343-1
Dashboard / Vulnerabilities / SUSE-SU-2016:0343-1
SUSE-SU-2016:0343-1
Summary: Security update for socat
Details: This update for socat fixes the following issues: - CVE-2013-3571: Fix a file descriptor leak that could have been misused for a denial of service attack against socat running in server mode (bsc#821985) - CVE-2014-0019: PROXY-CONNECT address was vulnerable to a stack buffer overflow (bsc#860991) - Fix a stack overflow in the parser that could have been leveraged to execute arbitrary code (bsc#964844)
References: https://www.suse.com/support/update/announcement/2016/suse-su-20160343-1/, https://bugzilla.suse.com/821985, https://bugzilla.suse.com/860991, https://bugzilla.suse.com/964844, https://www.suse.com/security/cve/CVE-2013-3571, https://www.suse.com/security/cve/CVE-2014-0019
Affected packages
Package
Name: socat
Purl: pkg:rpm/suse/socat&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
