Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
••••
KI & AI VideosJulian Goldie SEO: Jev AI Just Changed SEO Forever(29.09.2026 um 08:00 Uhr)
••••
Sichere ProgrammierungDurable AI Agents: Workflow Strategies for Resilient Systems(29.09.2026 um 07:29 Uhr)
•
Sichere ProgrammierungWhat If Your AI Agent Never Had to Leave the Browser?(29.09.2026 um 07:30 Uhr)
•••••
KI & AI VideosJulian Goldie SEO: Jev AI Just Changed SEO Forever(29.09.2026 um 08:00 Uhr)
••••
Sichere ProgrammierungDurable AI Agents: Workflow Strategies for Resilient Systems(29.09.2026 um 07:29 Uhr)
•
Sichere ProgrammierungWhat If Your AI Agent Never Had to Leave the Browser?(29.09.2026 um 07:30 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

curl: Memory leak in CURLOPT_XOAUTH2_BEARER

Summary: Once a bearer token is set with CURLOPT_XOAUTH2_BEARER, each HTTP request done with the same handler leaks the token itself. Steps To Reproduce: Given the following code: ```c include int main(void) { …

0
↗ Quelle (vulners.com)
Reagiere als Erste:r — dein Feedback zählt!

image
Summary: Once a bearer token is set with CURLOPT_XOAUTH2_BEARER, each HTTP request done with the same handler leaks the token itself. Steps To Reproduce: Given the following code: ```c include int main(void) { curl_global_init(CURL_GLOBAL_ALL); CURL* curl = curl_easy_init(); curl_easy_setopt(curl, CURLOPT_HTTPAUTH, CURLAUTH_BEARER); curl_easy_setopt(curl, CURLOPT_XOAUTH2_BEARER, "c4e448d652a961fda0ab64f882c8c161d5985f805d45d80c9ddca108f8e2fde3"); curl_easy_setopt(curl, CURLOPT_HTTPGET, 1L); curl_easy_setopt(curl, CURLOPT_URL, "https://andrea.pappacoda.it"); for (int i = 0; i < 5; i++) { curl_easy_perform(curl); } curl_easy_cleanup(curl); curl_global_cleanup(); } ``` AddressSanitizer reports a memory leak: ```text $ cc -g -fsanitize=address main.c $(pkg-config --cflags --libs libcurl) -o asan && ./asan ================================================================= ==41730==ERROR: LeakSanitizer: detected memory leaks Direct leak of 260 byte(s) in 4 object(s) allocated from: #0 0x7f52f54d97a7 in __interceptor_strdup ../../../../src/libsanitizer/asan/asan_interceptors.cpp:454 #1 0x7f52f54423cd (/lib/x86_64-linux-gnu/libcurl.so.4+0x673cd) SUMMARY: AddressSanitizer: 260 byte(s) leaked in 4 allocation(s). ``` and valgrind does too: text $ cc -g main.c $(pkg-config --cflags --libs libcurl) -o valgrind && valgrind --leak-check=full ./valgrind ==41878== ==41878== HEAP SUMMARY: ==41878== in use at exit: 3,710 bytes in 12 blocks ==41878== total heap...

2. Cyber Threat Intelligence & Forensik

IoC Intelligence (1 Indikatoren)
c4e448d652a961fda0ab64f882c8c161d5985f805d45d80c9ddca108f8e2fde3
CTI Threat Relationship Graph3 Knoten / 2 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten curl: Memory leak in CURLOPT_XOAUTH2_BEARER

Thematisch verwandte Begriffe: curl, Memory, leak, CURLOPTXOAUTH2BEARER · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-101281 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. …
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag