Описание
Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.
A use after free flaw has been discovered in the WebSocket server implementation of libwebsockets. The issue is caused by the lws_handshake_protocol function, specifically when the upgrade header is not valid, the function calls lws_http_transaction_completed, which frees some of the data in the wsi structure, then it calls user_callback_handle_rxflow passing the uppointer and uses it on following strcasecmp calls.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| A-MQ Interconnect 1 | libwebsockets | Fix deferred | ||
| Red Hat OpenStack Platform 16.2 | libwebsockets | Fix deferred | ||
| Red Hat OpenStack Platform 17.1 | libwebsockets | Fix deferred | ||
| Red Hat Service Interconnect 2 | libwebsockets | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.
Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.
Use After Free in WebSocket server implementation in lws_handshake_ser ...
Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.
EPSS
3.7 Low
CVSS3