Логотип exploitDog
bind:CVE-2024-6197
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-6197

Количество 10

Количество 10

ubuntu логотип

CVE-2024-6197

больше 1 года назад

libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack buffer. Most modern malloc implementations detect this error and immediately abort. Some however accept the input pointer and add that memory to its list of available chunks. This leads to the overwriting of nearby stack memory. The content of the overwrite is decided by the `free()` implementation; likely to be memory pointers and a set of flags. The most likely outcome of exploting this flaw is a crash, although it cannot be ruled out that more serious results can be had in special circumstances.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-6197

больше 1 года назад

libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack buffer. Most modern malloc implementations detect this error and immediately abort. Some however accept the input pointer and add that memory to its list of available chunks. This leads to the overwriting of nearby stack memory. The content of the overwrite is decided by the `free()` implementation; likely to be memory pointers and a set of flags. The most likely outcome of exploting this flaw is a crash, although it cannot be ruled out that more serious results can be had in special circumstances.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2024-6197

больше 1 года назад

libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack buffer. Most modern malloc implementations detect this error and immediately abort. Some however accept the input pointer and add that memory to its list of available chunks. This leads to the overwriting of nearby stack memory. The content of the overwrite is decided by the `free()` implementation; likely to be memory pointers and a set of flags. The most likely outcome of exploting this flaw is a crash, although it cannot be ruled out that more serious results can be had in special circumstances.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2024-6197

около 1 года назад

Hackerone: CVE-2024-6197 Freeing stack buffer in utf8asn1str

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2024-6197

больше 1 года назад

libcurl's ASN1 parser has this utf8asn1str() function used for parsing ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-x3h8-3mf2-v794

больше 1 года назад

libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack buffer. Most modern malloc implementations detect this error and immediately abort. Some however accept the input pointer and add that memory to its list of available chunks. This leads to the overwriting of nearby stack memory. The content of the overwrite is decided by the `free()` implementation; likely to be memory pointers and a set of flags. The most likely outcome of exploting this flaw is a crash, although it cannot be ruled out that more serious results can be had in special circumstances.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-06023

больше 1 года назад

Уязвимость функции utf8asn1str() парсера ASN1 утилиты командной строки cURL, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2784-1

около 1 года назад

Security update for curl

EPSS: Низкий
redos логотип

ROS-20240812-34

около 1 года назад

Уязвимость libcurl

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20240812-14

около 1 года назад

Уязвимость curl

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-6197

libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack buffer. Most modern malloc implementations detect this error and immediately abort. Some however accept the input pointer and add that memory to its list of available chunks. This leads to the overwriting of nearby stack memory. The content of the overwrite is decided by the `free()` implementation; likely to be memory pointers and a set of flags. The most likely outcome of exploting this flaw is a crash, although it cannot be ruled out that more serious results can be had in special circumstances.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-6197

libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack buffer. Most modern malloc implementations detect this error and immediately abort. Some however accept the input pointer and add that memory to its list of available chunks. This leads to the overwriting of nearby stack memory. The content of the overwrite is decided by the `free()` implementation; likely to be memory pointers and a set of flags. The most likely outcome of exploting this flaw is a crash, although it cannot be ruled out that more serious results can be had in special circumstances.

CVSS3: 5.9
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-6197

libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack buffer. Most modern malloc implementations detect this error and immediately abort. Some however accept the input pointer and add that memory to its list of available chunks. This leads to the overwriting of nearby stack memory. The content of the overwrite is decided by the `free()` implementation; likely to be memory pointers and a set of flags. The most likely outcome of exploting this flaw is a crash, although it cannot be ruled out that more serious results can be had in special circumstances.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-6197

Hackerone: CVE-2024-6197 Freeing stack buffer in utf8asn1str

CVSS3: 8.8
1%
Низкий
около 1 года назад
debian логотип
CVE-2024-6197

libcurl's ASN1 parser has this utf8asn1str() function used for parsing ...

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-x3h8-3mf2-v794

libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack buffer. Most modern malloc implementations detect this error and immediately abort. Some however accept the input pointer and add that memory to its list of available chunks. This leads to the overwriting of nearby stack memory. The content of the overwrite is decided by the `free()` implementation; likely to be memory pointers and a set of flags. The most likely outcome of exploting this flaw is a crash, although it cannot be ruled out that more serious results can be had in special circumstances.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-06023

Уязвимость функции utf8asn1str() парсера ASN1 утилиты командной строки cURL, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:2784-1

Security update for curl

около 1 года назад
redos логотип
ROS-20240812-34

Уязвимость libcurl

CVSS3: 7.5
1%
Низкий
около 1 года назад
redos логотип
ROS-20240812-14

Уязвимость curl

CVSS3: 7.5
1%
Низкий
около 1 года назад

Уязвимостей на страницу