First published: Tue Sep 05 2017(Updated: )
GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Embedthis GoAhead Web Server | =3.4.0 | |
Embedthis GoAhead Web Server | =3.4.1 | |
Embedthis GoAhead Web Server | =3.4.2 | |
Embedthis GoAhead Web Server | =3.4.3 | |
Embedthis GoAhead Web Server | =3.4.4 | |
Embedthis GoAhead Web Server | =3.4.5 | |
Embedthis GoAhead Web Server | =3.4.6 | |
Embedthis GoAhead Web Server | =3.4.7 | |
Embedthis GoAhead Web Server | =3.4.8 | |
Embedthis GoAhead Web Server | =3.4.9 | |
Embedthis GoAhead Web Server | =3.4.10 | |
Embedthis GoAhead Web Server | =3.4.11 | |
Embedthis GoAhead Web Server | =3.4.12 | |
Embedthis GoAhead Web Server | =3.5.0 | |
Embedthis GoAhead Web Server | =3.6.0 | |
Embedthis GoAhead Web Server | =3.6.1 | |
Embedthis GoAhead Web Server | =3.6.2 | |
Embedthis GoAhead Web Server | =3.6.3 | |
Embedthis GoAhead Web Server | =3.6.4 | |
Embedthis GoAhead Web Server | =3.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-14149 is considered moderate due to the potential for denial of service attacks.
To fix CVE-2017-14149, you should upgrade to GoAhead version 3.6.6 or later which addresses this NULL Pointer Dereference issue.
CVE-2017-14149 can lead to a crash of the GoAhead web server when it handles specially crafted HTTP POST requests.
CVE-2017-14149 affects GoAhead versions 3.4.0 to 3.6.5.
You can identify if your system is vulnerable to CVE-2017-14149 by checking the version of the GoAhead web server you are currently using.