dest-unreach / socat / contrib / security advisory 7
In the OpenSSL address implementation the hard coded 1024 bit DH p parameter was not prime. The effective cryptographic strength of a key exchange using these parameters was weaker than the one one could get by using a prime p. Moreover, since there is no indication of how these parameters were chosen, the existence of a trapdoor that makes possible for an eavesdropper to recover the shared secret from a key exchange that uses them cannot be ruled out.
A new prime modulus p parameter has been generated by Socat developer using OpenSSL dhparam command.
In addition the new parameter is 2048 bit long.
Socat security issue 7
220.127.116.11 - 18.104.22.168
22.214.171.124 and later
2.0.0-b1 - 2.0.0-b7
2.0.0-b9 and later
Disable DH ciphers.
The updated sources can be downloaded from:
Patch to 126.96.36.199:http://www.dest-unreach.org/socat/download/socat-188.8.131.52.patch
Patch to 2.0.0-b8:http://www.dest-unreach.org/socat/download/socat-2.0.0-b9.patch
Santiago Zanella-Beguelin and Microsoft Vulnerability Research (MSVR).