An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure.
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tizenrt | Samsung | 1.0-m1 (including) | 1.0-m1 (including) |
Tizenrt | Samsung | 1.1 (including) | 1.1 (including) |
Tizenrt | Samsung | 2.0 (including) | 2.0 (including) |
Tizenrt | Samsung | 3.0-gbm (including) | 3.0-gbm (including) |
0ad | Ubuntu | bionic | * |
0ad | Ubuntu | kinetic | * |
0ad | Ubuntu | lunar | * |
0ad | Ubuntu | mantic | * |
0ad | Ubuntu | trusty | * |
0ad | Ubuntu | xenial | * |