Double Free Vulnerability in uAMQP Could Lead to RCE
CVE-2024-27099
9.8CRITICAL
What is CVE-2024-27099?
The Azure uAMQP is a C library designed for AMQP 1.0 communication with Azure Cloud Services. A vulnerability exists within this library, which arises when processing an incorrect state of AMQP_VALUE. This improper handling can potentially lead to a double free condition, resulting in a scenario where an attacker might execute arbitrary code remotely. The issue is addressed in a recent commit, highlighting the importance of updating the submodule to the specified commit to mitigate security risks.
Affected Version(s)
azure-uamqp-c < 2023-2-08
