CVE-2020-15689: Null Pointer Dereference
Published Jul 13, 2020
·Updated
Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service.
Affected Software
2 affected components
Embedthis Appweb<7.2.2
Embedthis Appweb>=8.0.0<8.1.0
Event History
Jul 13, 2020
CVE Published
via MITRE·01:48 PM
Data Sourced
via MITRE·01:48 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-15689.
2
What is the severity of CVE-2020-15689?
The severity of CVE-2020-15689 is high (7.5).
3
Which software versions are affected by CVE-2020-15689?
Appweb versions before 7.2.2 and 8.x before 8.1.0 are affected by CVE-2020-15689.
4
What is the impact of CVE-2020-15689?
CVE-2020-15689 can result in a NULL pointer dereference and cause a denial of service.
5
How can I fix CVE-2020-15689?
The fix for CVE-2020-15689 is to upgrade to Appweb version 7.2.2 or 8.1.0 or later.