[SECURITY] Updated: socat 2.0.0-b8-1

Andrew Schulman schulman.andrew@epa.gov
Thu May 28 01:17:00 GMT 2015


A new version of socat, 2.0.0-b8-1, is available in the Cygwin distribution.
This release fixes a possible denial of service attack, so if you are currently
using an earlier 2.0.0-* release, you are urged to upgrade.  See
http://www.dest-unreach.org/socat/ for the full list of changes.

The 2.0.0-* series are test releases in Cygwin, so to get this update you'll
have to choose the "Exp" radio button in setup.

The current release of socat is still 1.7.3.0-2.

socat is a relay for bidirectional data transfer between two independent data
channels. Each of these data channels may be a file, pipe, device (serial line
etc. or a pseudo terminal), a socket (UNIX, IP4, IP6 - raw, UDP, TCP), an SSL
socket, proxy CONNECT connection, a file descriptor (stdin etc.), the GNU line
editor (readline), a program, or a combination of two of these. These modes
include generation of 'listening' sockets, named pipes, and pseudo terminals.
socat can be used, e.g., as TCP port forwarder (one-shot or daemon), as an
external socksifier, for attacking weak firewalls, as a shell interface to UNIX
sockets, IP6 relay, for redirecting TCP oriented programs to a serial line, to
logically connect serial lines on different computers, or to establish a
relatively secure environment (su and chroot) for running client or server shell
scripts with network connections.

Andrew E. Schulman


*******************************************************************


To update your installation, click on the "Install Cygwin now" link on
the http://cygwin.com/ web page.  This downloads setup.exe to your
system.  Then, run setup and answer all of the questions.

              *** CYGWIN-ANNOUNCE UNSUBSCRIBE INFO ***

If you want to unsubscribe from the cygwin-announce mailing list, look
at the "List-Unsubscribe: " tag in the email header of this message.
Send email to the address specified there.  It will be in the format:

cygwin-announce-unsubscribe-you=yourdomain.com_at_cygwin.com

If you need more information on unsubscribing, start reading here: 

http://cygwin.com/lists.html#subscribe-unsubscribe

Please read *all* of the information on unsubscribing that is available
starting at this URL.



More information about the Cygwin-announce mailing list