CVE-2004-1484: Medium severity socat socat vulnerability
Format string vulnerability in the msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1484?
CVE-2004-1484 is considered a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2004-1484?
To mitigate CVE-2004-1484, upgrade to a version of socat that is newer than 1.4.0.3.
What software is affected by CVE-2004-1484?
CVE-2004-1484 affects socat versions 1.4.0.3 and earlier when used as an HTTP proxy client.
Who can exploit CVE-2004-1484?
Both remote attackers and local users can exploit CVE-2004-1484 through format string specifiers in syslog messages.
What impact does CVE-2004-1484 have on systems?
CVE-2004-1484 can lead to arbitrary code execution, compromising system integrity and security.