CVE Vulnerabilities

CVE-2022-32962

Double Free

Published: Jul 20, 2022 | Modified: Aug 02, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Hicos_natural_person_credential_component_client Hinet 3.0.3.30306 (including) 3.0.3.30306 (including)
Hicos_natural_person_credential_component_client Hinet 3.0.3.30404 (including) 3.0.3.30404 (including)
Hicos_natural_person_credential_component_client Hinet 3.1.0.00002 (including) 3.1.0.00002 (including)

Potential Mitigations

References