PT-2019-15789 · Goahead · Goahead
Published
2019-11-22
·
Updated
2020-08-24
·
CVE-2019-19240
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GoAhead versions prior to 5.0.1
Description
The issue arises from the mishandling of redirected HTTP requests that contain a large Host header. Specifically, the GoAhead WebsRedirect utilizes a static host buffer with a limited length, which can overflow. This overflow can cause the copy of the Host header to fail, resulting in an uninitialized buffer. Consequently, uninitialized data may be leaked in a response.
Recommendations
For versions prior to 5.0.1, update to version 5.0.1 or later to resolve the issue.
Exploit
Fix
Use of Uninitialized Resource
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Goahead