Memory Exposure in tunnel-agent
Moderate severity
GitHub Reviewed
Published
Jun 3, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 3, 2019
Published to the GitHub Advisory Database
Jun 3, 2019
Last updated
Jan 9, 2023
Versions of
tunnel-agent
before 0.6.0 are vulnerable to memory exposure.This is exploitable if user supplied input is provided to the auth value and is a number.
Proof-of-concept:
Recommendation
Update to version 0.6.0 or later.
References