drachtio-server 0.8.18 has a request-handler.cpp event_cb use-after-free for any request.
[
{
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "275625140252032419450287838823633949408",
"length": 2541.0
},
"id": "CVE-2022-45474-244293ac",
"target": {
"file": "src/request-handler.cpp",
"function": "RequestHandler::startRequest"
},
"source": "https://github.com/drachtio/drachtio-server/commit/860f025468feb31c43227153d8fb3f34210a522e"
},
{
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"digest": {
"line_hashes": [
"158483295293576904124825594388491882108",
"107562715951715056429434249360572888512",
"55168409675127421493847497555339095056",
"115414229115053031577244473783664569304",
"119034032375418284031958587811169853123",
"276137244779172115892835726057672526782",
"305138473601715580700316391105548149115",
"329584203379882597084737539544215708235",
"333852299709108246174343443841297917218",
"225435003309004591100027601775260267134",
"127761345051944576977848658720862124857",
"271617997259688710728116901100653430858",
"136653259047622695317827124201165802974",
"250048289345750954184185833314107129962",
"75910259603644972785959500693890551595",
"167934851726581935525374188748344423878",
"77989704610967883821821799558442323285",
"75706225434171452274285747211308941689",
"142853282209738848086845856996194666967"
],
"threshold": 0.9
},
"id": "CVE-2022-45474-db878204",
"target": {
"file": "src/request-handler.cpp"
},
"source": "https://github.com/drachtio/drachtio-server/commit/860f025468feb31c43227153d8fb3f34210a522e"
},
{
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "218845617964931157765871159169050546266",
"length": 1280.0
},
"id": "CVE-2022-45474-e1b0b67b",
"target": {
"file": "src/request-handler.cpp",
"function": "event_cb"
},
"source": "https://github.com/drachtio/drachtio-server/commit/860f025468feb31c43227153d8fb3f34210a522e"
}
]