ALT-PU-2016-1789-1
Closed vulnerabilities
Published: 2017-01-31
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2016-2217
The OpenSSL address implementation in Socat 1.7.3.0 and 2.0.0-b8 does not use a prime number for the DH, which makes it easier for remote attackers to obtain the shared secret.
Severity: MEDIUM (5.3)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References:
- http://www.dest-unreach.org/socat/contrib/socat-secadv7.html
- http://www.dest-unreach.org/socat/contrib/socat-secadv7.html
- [oss-security] 20160201 Socat security advisory 7 - Created new 2048bit DH modulus
- [oss-security] 20160201 Socat security advisory 7 - Created new 2048bit DH modulus
- [oss-security] 20160203 Re: Socat security advisory 7 - Created new 2048bit DH modulus
- [oss-security] 20160203 Re: Socat security advisory 7 - Created new 2048bit DH modulus
- GLSA-201612-23
- GLSA-201612-23