mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 10:41:43 +00:00
20 lines
750 B
Markdown
20 lines
750 B
Markdown
![]() |
### [CVE-2023-52266](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52266)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
ehttp 1.0.6 before 17405b9 has an epoll_socket.cpp read_func use-after-free. An attacker can make many connections over a short time to trigger this.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://github.com/hongliuliao/ehttp/commit/17405b975948abc216f6a085d2d027ec1cfd5766
|
||
|
- https://github.com/hongliuliao/ehttp/issues/38
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/Halcy0nic/Trophies
|
||
|
- https://github.com/skinnyrad/Trophies
|
||
|
|