First published: Mon Jan 30 2017(Updated: )
The OpenSSL address implementation in Socat 1.7.3.0 and 2.0.0-b8 does not use a prime number for the DH, which makes it easier for remote attackers to obtain the shared secret.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
socat | =1.7.3.0 | |
socat | =2.0.0-b8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2217 is classified with a medium severity level due to its potential for remote exploitation.
To fix CVE-2016-2217, upgrade to a version of Socat that uses a prime number for the DH, such as Socat 1.7.3.1 or later.
Remote attackers can exploit CVE-2016-2217 to obtain the shared secret during the key exchange process.
CVE-2016-2217 affects Socat versions 1.7.3.0 and 2.0.0-b8.
Yes, users of the affected versions of Socat are at risk if they have not applied the necessary updates.