Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-27537

Опубликовано: 20 мар. 2023
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 3.1 on Red Hat Enterprise Linuxrh-dotnet31-curlNot affected
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlNot affected
Red Hat Enterprise Linux 8curlNot affected
Red Hat Enterprise Linux 9curlNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-curlNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-415

EPSS

Процентиль: 18%
0.00059
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 3 года назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
nvd
почти 3 года назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 5.9
debian
почти 3 года назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS ...

CVSS3: 5.9
github
почти 3 года назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

EPSS

Процентиль: 18%
0.00059
Низкий

5.6 Medium

CVSS3