Impact
A stack-based buffer overflow exists in the Header Handler of Ritlabs TinyWeb Server, triggered by malicious manipulation of the Authorization header processed in the libeay32.dll.html library. The flaw resides in an unknown function and occurs on Win32 systems running any release up to 1.94. Attackers can send crafted HTTP requests from a remote location to overflow the server’s stack, potentially leading to arbitrary code execution, loss of confidentiality, integrity, or availability of the affected services. The vulnerability is classified as CWE-119 and CWE-121, consistent with buffer and stack overflows.
Affected Systems
Ritlabs TinyWeb Server versions 1.94 and below running on Windows 32-bit platforms are affected. The vulnerability arises from the Header Handler component of the libeay32.dll.html library. No specific sub-versions are enumerated beyond the stated maximum of 1.94.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity, and the EPSS score is not available, providing little information about current exploitation prevalence. The vulnerability is listed as not in CISA KEV, suggesting no confirmed public exploitation yet, but the exploit has been disclosed publicly and is considered usable. Remote exploitation is possible with any client that can reach the server’s network interface, meaning the risk is contingent on the exposure of the server to untrusted networks. The lack of a vendor response reduces confidence in an imminent fix, increasing the importance of mitigations.
OpenCVE Enrichment