mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
20 lines
750 B
Markdown
20 lines
750 B
Markdown
### [CVE-2023-52266](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-52266)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
ehttp 1.0.6 before 17405b9 has an epoll_socket.cpp read_func use-after-free. An attacker can make many connections over a short time to trigger this.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://github.com/hongliuliao/ehttp/commit/17405b975948abc216f6a085d2d027ec1cfd5766
|
|
- https://github.com/hongliuliao/ehttp/issues/38
|
|
|
|
#### Github
|
|
- https://github.com/Halcy0nic/Trophies
|
|
- https://github.com/skinnyrad/Trophies
|
|
|