The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect AMQP_VALUE failed state, may cause a double free problem. This may cause a RCE. Update submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987.
{
"cwe_ids": [
"CWE-415"
]
}[
{
"source": "https://github.com/azure/azure-uamqp-c/commit/2ca42b6e4e098af2d17e487814a91d05f6ae4987",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2024-27099-6099aebe",
"target": {
"function": "link_frame_received",
"file": "src/link.c"
},
"digest": {
"length": 6095.0,
"function_hash": "244662739316117236140791295392823602087"
},
"signature_type": "Function"
},
{
"source": "https://github.com/azure/azure-uamqp-c/commit/2ca42b6e4e098af2d17e487814a91d05f6ae4987",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2024-27099-9e2db29f",
"target": {
"file": "src/link.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"108587633537507210242609878158511307392",
"160452673510098083035489543941216834770",
"112205478071487406712030953259419779646",
"119485482305993897163478625563792846654",
"45488740952744200082612943561926706776"
]
},
"signature_type": "Line"
}
]