Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | NVD-CWE-Other |
Mon, 18 Nov 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cesanta
Cesanta mongoose |
|
CPEs | cpe:2.3:a:cesanta:mongoose:*:*:*:*:*:*:*:* | |
Vendors & Products |
Cesanta
Cesanta mongoose |
|
Metrics |
ssvc
|
Mon, 18 Nov 2024 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. | |
Title | Use of Out-of-range Pointer Offset in Mongoose Web Server library | |
Weaknesses | CWE-823 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Nozomi
Published: 2024-11-18T09:06:44.153Z
Updated: 2024-11-18T13:37:37.168Z
Reserved: 2024-07-31T12:51:37.203Z
Link: CVE-2024-42388
Vulnrichment
Updated: 2024-11-18T13:37:22.206Z
NVD
Status : Analyzed
Published: 2024-11-18T10:15:07.873
Modified: 2024-11-19T17:51:24.567
Link: CVE-2024-42388
Redhat
No data.