The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect AMQP_VALUE
failed state, may cause a double free problem. This may cause a RCE. Update submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987.
{ "cwe_ids": [ "CWE-415" ] }
[ { "deprecated": false, "source": "https://github.com/azure/azure-uamqp-c/commit/2ca42b6e4e098af2d17e487814a91d05f6ae4987", "signature_type": "Function", "id": "CVE-2024-27099-6099aebe", "digest": { "length": 6095.0, "function_hash": "244662739316117236140791295392823602087" }, "target": { "file": "src/link.c", "function": "link_frame_received" }, "signature_version": "v1" }, { "deprecated": false, "source": "https://github.com/azure/azure-uamqp-c/commit/2ca42b6e4e098af2d17e487814a91d05f6ae4987", "signature_type": "Line", "id": "CVE-2024-27099-9e2db29f", "digest": { "line_hashes": [ "108587633537507210242609878158511307392", "160452673510098083035489543941216834770", "112205478071487406712030953259419779646", "119485482305993897163478625563792846654", "45488740952744200082612943561926706776" ], "threshold": 0.9 }, "target": { "file": "src/link.c" }, "signature_version": "v1" } ]