← back
CVE-2024-54661criticalCWE-61

CVE-2024-54661

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 0.8%
exploitation probability
0.8%top 46% of all CVEs
observed exploitation
nono source reports it
In short

socat versions before 1.8.0.2 use a predictable temporary file in /tmp that can be hijacked by other users on the same system to execute arbitrary code with the privileges of the socat process.

Technical detail

CWE-61 (TOCTOU) vulnerability in readline.sh allows local privilege escalation via symlink attack against the /tmp/$USER/stderr2 file. An attacker can create a symlink to overwrite arbitrary files or inject malicious code executed in the socat process context, requiring only local file system access.

Summary generated and translated by AI from the official description.
readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
dest-unreach · socat