PT-2019-15789 · Goahead · Goahead

Publicado

2019-11-22

·

Atualizado

2020-08-24

·

CVE-2019-19240

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GoAhead versions prior to 5.0.1
Description The issue arises from the mishandling of redirected HTTP requests that contain a large Host header. Specifically, the GoAhead WebsRedirect utilizes a static host buffer with a limited length, which can overflow. This overflow can cause the copy of the Host header to fail, resulting in an uninitialized buffer. Consequently, uninitialized data may be leaked in a response.
Recommendations For versions prior to 5.0.1, update to version 5.0.1 or later to resolve the issue.

Exploit

Correção

Use of Uninitialized Resource

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-19240

Produtos afetados

Goahead