CVE-2012-0219

medium
Published 2012-06-21 · Modified 2026-04-29
CVSS v3
CVSS v2
6.2
VIR risk
6.2

Description

Heap-based buffer overflow in the xioscan_readline function in xio-readline.c in socat 1.4.0.0 through 1.7.2.0 and 2.0.0-b1 through 2.0.0-b4 allows local users to execute arbitrary code via the READLINE address.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-0219

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://www.dest-unreach.org/socat/contrib/socat-secadv3.html

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://secunia.com/advisories/49105

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.7.1.3-1.3
debian debianbullseyefixed1.7.1.3-1.3
debian debianforkyfixed1.7.1.3-1.3
debian debiansidfixed1.7.1.3-1.3
debian debiantrixiefixed1.7.1.3-1.3

Application impact

VendorProductVersionsFixed
dest-unreachsocat1.4.0.0
dest-unreachsocat1.4.0.1
dest-unreachsocat1.4.0.2
dest-unreachsocat1.4.0.3
dest-unreachsocat1.4.1.0
dest-unreachsocat1.4.2.0
dest-unreachsocat1.4.3.1
dest-unreachsocat1.5.0.0
dest-unreachsocat1.6.0.0
dest-unreachsocat1.6.0.1
dest-unreachsocat1.7.0.0
dest-unreachsocat1.7.0.1
dest-unreachsocat1.7.1.0
dest-unreachsocat1.7.1.1
dest-unreachsocat1.7.1.2
dest-unreachsocat1.7.1.3
dest-unreachsocat1.7.2.0
dest-unreachsocat2.0.0

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.