CVE-2014-0019

low
Published 2014-02-04 · Modified 2026-04-29
CVSS v3
CVSS v2
1.9
VIR risk
1.9

Description

Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-0019

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.dest-unreach.org/socat

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://seclists.org/oss-sec/2014/q1/159

OS impact

OSVersionStatusFixed in
suse suse13.1affected
fedora fedora19affected
fedora fedora20affected
debian debianbookwormfixed1.7.2.3-1
debian debianbullseyefixed1.7.2.3-1
debian debianforkyfixed1.7.2.3-1
debian debiansidfixed1.7.2.3-1
debian debiantrixiefixed1.7.2.3-1

Application impact

VendorProductVersionsFixed
dest-unreachsocat2.0.0
dest-unreachsocat1.3.0.0
dest-unreachsocat1.3.0.1
dest-unreachsocat1.3.1.0
dest-unreachsocat1.3.2.0
dest-unreachsocat1.3.2.1
dest-unreachsocat1.3.2.2
dest-unreachsocat1.4.0.0
dest-unreachsocat1.4.0.1
dest-unreachsocat1.4.0.2
dest-unreachsocat1.4.0.3
dest-unreachsocat1.4.1.0
dest-unreachsocat1.4.2.0
dest-unreachsocat1.4.3.0
dest-unreachsocat1.4.3.1
dest-unreachsocat1.5.0.0
dest-unreachsocat1.6.0.0
dest-unreachsocat1.6.0.1
dest-unreachsocat1.7.0.0
dest-unreachsocat1.7.0.1
dest-unreachsocat1.7.1.0
dest-unreachsocat1.7.1.1
dest-unreachsocat1.7.1.2
dest-unreachsocat1.7.1.3
dest-unreachsocat1.7.2.0
dest-unreachsocat1.7.2.1
dest-unreachsocat1.7.2.2

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.