It is reported that jwhois is susceptible to a double free vulnerability. If jwhois attempts to process whois requests that result in more than one redirection, it is reported that a double free condition will occur. It is conjectured that it may be possible for remote attackers to exploit this vulnerability to write to arbitrary locations in memory, facilitating the execution of attacker-supplied code. This has not been confirmed. This vulnerability may not actually be exploitable. This BID will be updated or retired as further information is disclosed.
It is reported that jwhois is susceptible to a double free vulnerability. If jwhois attempts to process whois requests that result in more than one redirection, it is reported that a double free condition will occur. It is conjectured that it may be possible for remote attackers to exploit this vulnerability to write to arbitrary locations in memory, facilitating the execution of attacker-supplied code. This has not been confirmed. This vulnerability may not actually be exploitable. This BID will be updated or retired as further information is disclosed.