Safeguard
Tag

heap-overflow

Safeguard articles tagged "heap-overflow" — guides, analysis, and best practices for software supply chain and application security.

7 articles

Vulnerability Analysis

curl SOCKS5 Heap Overflow (CVE-2023-38545) Explained: When a Long Hostname Broke the Handshake

CVE-2023-38545 is a heap buffer overflow in curl and libcurl's SOCKS5 proxy handshake, triggered when a too-long hostname is copied into a fixed buffer during a slow handshake. Here is the bug.

Jul 8, 20266 min read
Vulnerability Management

Inside CVE-2023-38545: the libcurl SOCKS5 heap overflow

A single off-by-length check in curl's SOCKS5 handshake, live for over three years across libcurl 7.69.0–8.3.x, earned a 9.8 CVSS score and a CWE-787 out-of-bounds write.

Jul 8, 20266 min read
Vulnerability Analysis

WebP (CVE-2023-4863) Explained: The libwebp Heap Overflow That Patched the Web

CVE-2023-4863 was an actively exploited heap buffer overflow in libwebp's Huffman decoder. Because the codec is vendored everywhere, one bug forced emergency patches across browsers and apps.

Jul 3, 20266 min read
Vulnerability Analysis

Git Heap Buffer Overflow via GIT_PUSH_OPTION_COUNT (CVE-2...

CVE-2022-39260 is a heap overflow in Git from an integer overflow in GIT_PUSH_OPTION_COUNT during git push. What changed, and how to remediate it.

Nov 27, 20257 min read
Security

libwebp Vulnerability: What CVE-2023-4863 Means and How to Fix It

The libwebp vulnerability CVE-2023-4863 was a heap buffer overflow exploited in the wild. Here is what it affected, why it was everywhere, and how to fix it.

Nov 6, 20256 min read
Security

CVE-2021-43527: The NSS Heap Overflow Explained

CVE-2021-43527 is a critical heap buffer overflow in Mozilla NSS that can lead to remote code execution when verifying certain digital signatures.

Aug 14, 20255 min read
Vulnerability Analysis

curl CVE-2023-38545: The Worst curl Vulnerability in Years

A heap buffer overflow in curl's SOCKS5 proxy handshake earned a severity rating of HIGH from curl's creator Daniel Stenberg, who called it the worst curl flaw in a long time.

Oct 11, 20235 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

heap-overflow — Safeguard Blog