PT-2020-16185 · Cesanta · Mongoose

Bushraalorainio

·

Published

2020-09-18

·

Updated

2024-08-04

·

CVE-2020-25756

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cesanta Mongoose version 6.18
Description A buffer overflow issue exists in the mg get http header function due to a lack of bounds checking, which can be exploited by a crafted HTTP header.
Recommendations For Cesanta Mongoose version 6.18, consider applying bounds checking to the mg get http header function to prevent buffer overflow exploitation. As a temporary workaround, restrict the use of crafted HTTP headers until a patch is available.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2020-25756

Affected Products

Mongoose