The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other requests.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-38288 | The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other requests. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 28 Feb 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 02 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1284 | |
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-28T13:07:27.141Z
Reserved: 2023-05-30T00:00:00.000Z
Link: CVE-2023-34188
Updated: 2025-02-28T13:07:27.141Z
Status : Modified
Published: 2023-06-23T20:15:09.053
Modified: 2025-02-28T13:15:26.103
Link: CVE-2023-34188
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD