Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-39588 Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
Fixes

Solution

It is suggested to update the Mongoose Web Server library to v7.15.


Workaround

It is highly recommended to not expose the vulnerable component inside an untrusted network.

References
History

Tue, 14 Jan 2025 08:45:00 +0000


Mon, 13 Jan 2025 10:45:00 +0000

Type Values Removed Values Added
References

Mon, 18 Nov 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Cesanta
Cesanta mongoose
CPEs cpe:2.3:a:cesanta:mongoose:*:*:*:*:*:*:*:*
Vendors & Products Cesanta
Cesanta mongoose
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 09:30:00 +0000

Type Values Removed Values Added
Description Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
Title Integer Overflow or Wraparound in Mongoose Web Server library
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2025-01-13T10:39:38.335Z

Reserved: 2024-07-31T12:51:37.203Z

Link: CVE-2024-42384

cve-icon Vulnrichment

Updated: 2024-11-18T13:39:21.164Z

cve-icon NVD

Status : Modified

Published: 2024-11-18T10:15:06.943

Modified: 2025-01-13T11:15:07.020

Link: CVE-2024-42384

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.