PT-2019-15789 · Goahead · Goahead
Publicado
2019-11-22
·
Atualizado
2020-08-24
·
CVE-2019-19240
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GoAhead versions prior to 5.0.1
Description
The issue arises from the mishandling of redirected HTTP requests that contain a large Host header. Specifically, the GoAhead WebsRedirect utilizes a static host buffer with a limited length, which can overflow. This overflow can cause the copy of the Host header to fail, resulting in an uninitialized buffer. Consequently, uninitialized data may be leaked in a response.
Recommendations
For versions prior to 5.0.1, update to version 5.0.1 or later to resolve the issue.
Exploit
Correção
Use of Uninitialized Resource
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Goahead