Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39587 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field. |
Solution
It is suggested to update the Mongoose Web Server library to v7.15.
Workaround
It is highly recommended to not expose the vulnerable component inside an untrusted network.
Tue, 19 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cesanta
Cesanta mongoose |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:cesanta:mongoose:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cesanta
Cesanta mongoose |
Mon, 18 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 18 Nov 2024 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field. | |
| Title | Use of Out-of-range Pointer Offset in Mongoose Web Server library | |
| Weaknesses | CWE-823 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2024-11-18T13:36:30.205Z
Reserved: 2024-07-31T12:51:37.203Z
Link: CVE-2024-42383
Updated: 2024-11-18T13:36:14.838Z
Status : Analyzed
Published: 2024-11-18T10:15:06.667
Modified: 2024-11-19T17:55:22.020
Link: CVE-2024-42383
No data.
OpenCVE Enrichment
No data.
EUVD