- Description
- An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- nvd@nist.gov
- CWE-401
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:samsung:tizenrt:1.0:m1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6B59E31E-7082-4719-97B6-3ADA43058E65"
},
{
"criteria": "cpe:2.3:o:samsung:tizenrt:1.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E625EE90-3CB6-4405-8827-355369A5917E"
},
{
"criteria": "cpe:2.3:o:samsung:tizenrt:2.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4EF9DBF2-9C4A-42C2-A799-922485902209"
},
{
"criteria": "cpe:2.3:o:samsung:tizenrt:3.0:gbm:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59AD1A65-ECC5-4DC0-A7BB-C616E24A42A2"
}
],
"operator": "OR"
}
]
}
]