Back

CVE-2004-1484

Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (16)

Vendor Product Version
socat socat 1.0.3.0
socat socat 1.0.4.0
socat socat 1.0.4.1
socat socat 1.0.4.2
socat socat 1.1.0.0
socat socat 1.1.0.1
socat socat 1.2.0.0
socat socat 1.3.0.0
socat socat 1.3.0.1
socat socat 1.3.1.0
socat socat 1.3.2.0
socat socat 1.3.2.1
socat socat 1.3.2.2
socat socat 1.4.0.0
socat socat 1.4.0.1
socat socat 1.4.0.2

GitHub Security Advisory GHSA-v3f9-7x42-4vg2

Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 7.29%

Top 6% most likely to be exploited

Threat Score 22.2 / 100

Data Sources

NVD EPSS GitHub