PT-2024-24236 · Unknown · Goahead Web Server
Diego Zaffaroni
·
Published
2024-10-17
·
Updated
2024-10-18
·
CVE-2024-3184
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GoAhead Web Server versions up to 6.0.0
Description
Multiple NULL Pointer Dereference vulnerabilities were found in GoAhead Web Server when compiled with the ME GOAHEAD REPLACE MALLOC flag. Without a memory notifier for allocation failures, remote attackers can exploit these vulnerabilities by sending malicious requests, leading to a crash and Denial of Service (DoS).
Recommendations
For GoAhead Web Server versions up to 6.0.0, consider disabling the ME GOAHEAD REPLACE MALLOC flag as a temporary workaround to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Goahead Web Server