PT-2021-22928 · Unknown · Ulfius Http Framework

Jeremy Brown

·

Published

2021-09-07

·

Updated

2024-06-15

·

CVE-2021-40540

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ulfius HTTP Framework versions prior to 2.7.4
Description The issue arises from the ulfius uri logger in the Ulfius HTTP Framework, which fails to initialize con info and perform a con info->request NULL check for certain malformed HTTP requests. This can lead to remote memory corruption.
Recommendations For versions prior to 2.7.4, update to version 2.7.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the ulfius uri logger function until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-40540
OPENSUSE-SU-2024:11481-1

Affected Products

Ulfius Http Framework