CVE-2018-20355: Use After Free
Published Jun 10, 2019
·Updated
An invalid write of 8 bytes due to a use-after-free vulnerability in the mghttpfreeprotodatacgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.
Affected Software
1 affected component
Cesanta Mongoose<=6.13
Event History
Jun 10, 2019
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-20355.
2
What is the severity of CVE-2018-20355?
The severity of CVE-2018-20355 is critical with a CVSS score of 9.8.
3
What is the affected software?
The affected software is Cesanta Mongoose Embedded Web Server Library version 6.13 and earlier.
4
What is the impact of CVE-2018-20355?
CVE-2018-20355 can lead to a denial of service (application crash) or remote code execution.
5
Is there a fix available for CVE-2018-20355?
Yes, it is recommended to update to a version of Cesanta Mongoose that is not affected by this vulnerability.