Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary string.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T15:56:36.110Z
Reserved: 2017-03-19T00:00:00
Link: CVE-2017-7185
No data.
Status : Deferred
Published: 2017-04-10T15:59:00.503
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-7185
No data.
OpenCVE Enrichment
No data.
Weaknesses