VDB

GCVE-110-MAGEIA-2014-70

GCVE-110-MAGEIA-2014-70
Advisory Published
Vulnetix · Advisory published February 16, 2014
Due to a missing check in socat before 2.0.0-b7 during assembly of the HTTP request line, a long target server name (<hostname> in the documentation) in the PROXY-CONNECT address can cause a stack buffer overrun. Exploitation requires that the attacker is able to provide the target server name to the PROXY-CONNECT address in the command line. This can happen, for example, in scripts that receive data from untrusted sources (CVE-2014-0019).

Affected Products

VendorProductVersionsPlatforms
Mageiaphp-pear-PHP_Fork0 (affected), 0.3.2-3.2.mga4 (unaffected)
Mageiasocat0 (affected), 2.0.0-0.b7.1.mga4 (unaffected), 0 (affected), 2.0.0-0.b7.1.mga4 (unaffected)
Mageiasocat0 (affected), 0 (affected), 2.0.0-0.b7.1.mga3 (unaffected), 2.0.0-0.b7.1.mga3 (unaffected)
Mageiaphp-pear-PHP_Fork0 (affected), 0.3.2-2.1.mga3 (unaffected)

Browse GCVE Records

74,265 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›