First published: Mon Jul 13 2020(Updated: )
Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Embedthis Appweb | <7.2.2 | |
Embedthis Appweb | >=8.0.0<8.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-15689.
The severity of CVE-2020-15689 is high (7.5).
Appweb versions before 7.2.2 and 8.x before 8.1.0 are affected by CVE-2020-15689.
CVE-2020-15689 can result in a NULL pointer dereference and cause a denial of service.
The fix for CVE-2020-15689 is to upgrade to Appweb version 7.2.2 or 8.1.0 or later.