Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-27537

Опубликовано: 30 мар. 2023
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 5.9

Описание

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

РелизСтатусПримечание
bionic

not-affected

devel

not-affected

7.88.1-6ubuntu2
esm-infra-legacy/trusty

not-affected

esm-infra/bionic

not-affected

esm-infra/focal

not-affected

esm-infra/xenial

not-affected

focal

not-affected

jammy

not-affected

kinetic

not-affected

7.85.0-1ubuntu0.3
lunar

released

7.88.1-6ubuntu2

Показывать по

EPSS

Процентиль: 16%
0.00053
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.6
redhat
больше 2 лет назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
nvd
больше 2 лет назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 5.9
debian
больше 2 лет назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS ...

CVSS3: 5.9
github
больше 2 лет назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

EPSS

Процентиль: 16%
0.00053
Низкий

5.9 Medium

CVSS3