The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect AMQP_VALUE failed state, may cause a double free problem. This may cause a RCE. Update submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987.
The product calls free() twice on the same memory address.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Azure_uamqp | Microsoft | * | 2023-2-08 (excluding) | 
| Azure-uamqp-python | Ubuntu | focal | * | 
| Azure-uamqp-python | Ubuntu | mantic | * | 
| Azure-uamqp-python | Ubuntu | oracular | * |