An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure.
2022-09-08T22:15:08.843
2024-11-21T07:21:11.263
Modified
CVSSv3.1: 7.5 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | samsung | tizenrt | 1.0 | Yes |
| Operating System | samsung | tizenrt | 1.1 | Yes |
| Operating System | samsung | tizenrt | 2.0 | Yes |
| Operating System | samsung | tizenrt | 3.0 | Yes |