CVE Vulnerabilities

CVE-2022-32962

Double Free

Published: Jul 20, 2022 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
Hicos_natural_person_credential_component_clientHinet3.0.3.30306 (including)3.0.3.30306 (including)
Hicos_natural_person_credential_component_clientHinet3.0.3.30404 (including)3.0.3.30404 (including)
Hicos_natural_person_credential_component_clientHinet3.1.0.00002 (including)3.1.0.00002 (including)

Potential Mitigations

References