First published: Mon Jun 10 2019(Updated: )
An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cesanta Mongoose | <=6.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-20355.
The severity of CVE-2018-20355 is critical with a CVSS score of 9.8.
The affected software is Cesanta Mongoose Embedded Web Server Library version 6.13 and earlier.
CVE-2018-20355 can lead to a denial of service (application crash) or remote code execution.
Yes, it is recommended to update to a version of Cesanta Mongoose that is not affected by this vulnerability.