#VU87850 Missing Release of Resource after Effective Lifetime in cURL - CVE-2024-2398
Published: March 27, 2024
cURL
curl.haxx.se
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error when sending HTTP/2 server push responses with an overly large number of headers. A remote attacker can send PUSH_PROMISE frames with an excessive amount of headers to the application, trigger memory leak and perform a denial of service (DoS) attack.