Описание
When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.
Ссылки
- PatchVendor Advisory
- Vendor Advisory
- ExploitIssue TrackingThird Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
EPSS
7.5 High
CVSS3
Дефекты
Связанные уязвимости
When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.
A flaw was found in curl. When handling a second Server Message Block (SMB) request to the same host, curl incorrectly accesses memory that has already been freed. This memory corruption vulnerability, known as a use-after-free, could allow a remote attacker to potentially execute arbitrary code or cause a denial of service.
When doing a second SMB request to the same host again, curl would wro ...
When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.
EPSS
7.5 High
CVSS3