PT-2019-15789 · Goahead · Goahead

Published

2019-11-22

·

Updated

2020-08-24

·

CVE-2019-19240

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GoAhead versions prior to 5.0.1
Description The issue arises from the mishandling of redirected HTTP requests that contain a large Host header. Specifically, the GoAhead WebsRedirect utilizes a static host buffer with a limited length, which can overflow. This overflow can cause the copy of the Host header to fail, resulting in an uninitialized buffer. Consequently, uninitialized data may be leaked in a response.
Recommendations For versions prior to 5.0.1, update to version 5.0.1 or later to resolve the issue.

Exploit

Fix

Use of Uninitialized Resource

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19240

Affected Products

Goahead