Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Link | Tags |
---|---|
https://github.com/gpg/boa/pull/1 | third party advisory |
https://github.com/gpg/boa/pull/1/commits/e139b87835994d007fbd64eead6c1455d7b8cf4e | third party advisory patch |