Zsh Mailing List Archive
Messages sorted by: Reverse Date, Date, Thread, Author

User after Free in zftp module



Hello,

There is a security vulnerablity in zftp module.
At `https://github.com/zsh-users/zsh/blob/acdcf9d8542a4461c0fceb98fdfef7380a128f78/Src/Modules/zftp.c#L3149`, `zfsessions` is begin freed but the variable is not set to NULL afterwards which leads to a "Use after Free" bug. 

Regards,


Messages sorted by: Reverse Date, Date, Thread, Author