DescriptionThe OpenSSL address implementation in Socat 126.96.36.199 and 2.0.0-b8 does not use a prime number for the DH, which makes it easier for remote attackers to obtain the shared secret.
Overall state of this security issue: Does not affect SUSE products
Note from the SUSE Security TeamWe have not shipped the affected socat version, so SUSE Linux Enterprise 12 and older were not affected. SUSE Bugzilla entry: 964843 [RESOLVED / FIXED] No SUSE Security Announcements cross referenced.
SUSE Timeline for this CVECVE page created: Fri Oct 7 12:47:33 2022
CVE page last modified: Fri Oct 7 12:47:33 2022