CVE Vulnerabilities

CVE-2023-36420

Double Free

Published: Oct 10, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
Odbc_driver_for_sql_serverMicrosoft17 (including)17.10.5.1 (excluding)
Odbc_driver_for_sql_serverMicrosoft17.0.1.1 (including)17.10.5.1 (excluding)
Odbc_driver_for_sql_serverMicrosoft18.0 (including)18.3.2.1 (excluding)
Odbc_driver_for_sql_serverMicrosoft18.0.1.1 (including)18.3.2.1 (excluding)
Sql_serverMicrosoft2019 (including)2019 (including)
Sql_serverMicrosoft2022 (including)2022 (including)

Potential Mitigations

References