CVE-2021-33304: Double Free
Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/picofragments.c in function picofragmentsreassemble, allows attackers to execute arbitrary code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33304?
The severity of CVE-2021-33304 is critical with a CVSS score of 9.8.
How does the Double Free vulnerability in virtualsquare picoTCP work?
The Double Free vulnerability in virtualsquare picoTCP allows attackers to execute arbitrary code by exploiting a flaw in the pico_fragments_reassemble function in modules/pico_fragments.c.
Which software versions are affected by CVE-2021-33304?
CVE-2021-33304 affects Altran picoTCP version 1.7.0 and Altran Picotcp-ng version 2.1.
Is there a fix available for CVE-2021-33304?
At the time of this writing, there is no specific fix available for CVE-2021-33304. It is recommended to follow the GitHub issue for updates.
Where can I find more information about CVE-2021-33304?
You can find more information about CVE-2021-33304 in the GitHub issue: https://github.com/virtualsquare/picotcp/issues/6.