CVE-2017-14149: Null Pointer Dereference
Published Sep 5, 2017
·Updated
GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" request.
Affected Software
20 affected components
Embedthis GoAhead=3.4.0
Embedthis GoAhead=3.4.1
Embedthis GoAhead=3.4.2
Embedthis GoAhead=3.4.3
Embedthis GoAhead=3.4.4
Embedthis GoAhead=3.4.5
Embedthis GoAhead=3.4.6
Embedthis GoAhead=3.4.7
Embedthis GoAhead=3.4.8
Embedthis GoAhead=3.4.9
Embedthis GoAhead=3.4.10
Embedthis GoAhead=3.4.11
Embedthis GoAhead=3.4.12
Embedthis GoAhead=3.5.0
Embedthis GoAhead=3.6.0
Embedthis GoAhead=3.6.1
Embedthis GoAhead=3.6.2
Embedthis GoAhead=3.6.3
Embedthis GoAhead=3.6.4
Embedthis GoAhead=3.6.5
Event History
Sep 5, 2017
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14149?
The severity of CVE-2017-14149 is considered moderate due to the potential for denial of service attacks.
2
How do I fix CVE-2017-14149?
To fix CVE-2017-14149, you should upgrade to GoAhead version 3.6.6 or later which addresses this NULL Pointer Dereference issue.
3
What impact does CVE-2017-14149 have on my server?
CVE-2017-14149 can lead to a crash of the GoAhead web server when it handles specially crafted HTTP POST requests.
4
Which versions of GoAhead are affected by CVE-2017-14149?
CVE-2017-14149 affects GoAhead versions 3.4.0 to 3.6.5.
5
How can I identify if my system is vulnerable to CVE-2017-14149?
You can identify if your system is vulnerable to CVE-2017-14149 by checking the version of the GoAhead web server you are currently using.