CVE-2004-1484

socat 1.4.0.3 - Remote Code Execution via Format String in Syslog Message

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1484. PoCs published by CoKi.

AI-analyzed exploit summary This exploit targets a format string vulnerability in socat <= 1.4.0.2, leveraging a local exploit to overwrite the .dtors section with shellcode. It uses a format string attack to redirect execution to the shellcode, which spawns a shell.

Description

Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.

Exploits (1)

exploitdb WORKING POC VERIFIED
by CoKi · clocallinux
https://www.exploit-db.com/exploits/591

This exploit targets a format string vulnerability in socat <= 1.4.0.2, leveraging a local exploit to overwrite the .dtors section with shellcode. It uses a format string attack to redirect execution to the shellcode, which spawns a shell.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: socat <= 1.4.0.2
No auth needed
Prerequisites: Local access to the target system · socat binary installed at /usr/local/bin/socat · objdump and grep utilities available
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Patch, Vendor Advisory x_refsource_misc
http://www.nosystem.com.ar/advisories/advisory-07.txt
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12936/
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11505
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17822
Patch, Vendor Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200410-26.xml

Scores

EPSS 0.0729
EPSS Percentile 93.6%

Details

Status published
Products (16)
socat/socat 1.0.3.0
socat/socat 1.0.4.0
socat/socat 1.0.4.1
socat/socat 1.0.4.2
socat/socat 1.1.0.0
socat/socat 1.1.0.1
socat/socat 1.2.0.0
socat/socat 1.3.0.0
socat/socat 1.3.0.1
socat/socat 1.3.1.0
... and 6 more
Published Dec 31, 2004
Tracked Since Feb 18, 2026