CVE-2018-15505: Null Pointer Dereference
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15505?
The severity of CVE-2018-15505 is considered moderate due to its potential to cause a denial of service.
How do I fix CVE-2018-15505?
To fix CVE-2018-15505, you should upgrade Embedthis GoAhead to version 4.0.1 or Appweb to version 7.0.2 or later.
What types of systems are affected by CVE-2018-15505?
CVE-2018-15505 affects Embedthis GoAhead versions prior to 4.0.1 and Appweb versions prior to 7.0.2, as well as specific Juniper JUNOS versions.
Can CVE-2018-15505 be exploited remotely?
Yes, CVE-2018-15505 can be exploited remotely through crafted HTTP POST requests.
What impact can an attacker have if exploiting CVE-2018-15505?
An attacker exploiting CVE-2018-15505 could cause a denial of service by triggering a NULL pointer dereference.