Description
A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invokes request error handling in a specific sequence. This issue affects versions of proxygen prior to v2020.05.18.00.
Affected products
- Facebook / proxygenunspecified – v2020.05.18.00
- Facebook / proxygenv2020.05.18.00 – unspecified
References
- VENDOR_ADVISORYhttps://www.facebook.com/security/advisories/cve-2020-1897
Updated 16m ago · 8 sources