CVE-2019-19240: Medium severity embedthis goahead web server vulnerability
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow. This can cause a copy of the Host header to fail, leaving that buffer uninitialized, which may leak uninitialized data in a response.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Embedthis GoAhead before 5.0.1?
The vulnerability ID for Embedthis GoAhead before 5.0.1 is CVE-2019-19240.
What is the severity of CVE-2019-19240?
The severity of CVE-2019-19240 is medium with a severity value of 5.3.
How does Embedthis GoAhead before 5.0.1 mishandle redirected HTTP requests?
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header, causing a buffer overflow.
How can the vulnerability CVE-2019-19240 be exploited?
The vulnerability CVE-2019-19240 can be exploited by sending redirected HTTP requests with a large Host header, which triggers a buffer overflow.
How can I fix the vulnerability in Embedthis GoAhead?
To fix the vulnerability in Embedthis GoAhead, update to version 5.0.1 or higher.