Description
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the first return value of a function is dereferenced even when the function returns an error. This can result in a nil dereference, and cause code to panic. This vulnerability is fixed in 2.1.0.
Problem types
CWE-476: NULL Pointer Dereference
Product status
References
github.com/...gonfly/security/advisories/GHSA-4mhv-8rh3-4ghw
github.com/...curity/dragonfly-comprehensive-report-2023.pdf