{"id":"MGASA-2016-0053","summary":"Updated socat packages fix security vulnerability","details":"In socat before 2.0.0-b9, in the OpenSSL address implementation, the hard\ncoded 1024 bit DH p parameter was not prime. It may be possible for an\neavesdropper to recover the shared secret from a key exchange\n(CVE-2016-2217).\n\nIn socat before 2.0.0-b9, a stack overflow vulnerability was found that\ncan be triggered when command line arguments are longer than 512 bytes.\nThis vulnerability can only be exploited when an attacker is able to\ninject data into socat's command line.\n","modified":"2026-04-16T06:23:38.239002274Z","published":"2016-02-05T17:26:09Z","upstream":["CVE-2016-2217"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0053.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=17661"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2016/02/01/4"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2016/02/01/5"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2016/02/04/1"}],"affected":[{"package":{"name":"socat","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/socat?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.0-0.b9.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0053.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}