First published: Fri Sep 18 2020(Updated: )
** DISPUTED ** A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking. A crafted HTTP header can exploit this bug. NOTE: a committer has stated "this will not happen in practice."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cesanta Mongoose | =6.18 | |
=6.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25756 is a buffer overflow vulnerability in the mg_get_http_header function in Cesanta Mongoose 6.18.
CVE-2020-25756 has a severity rating of 9.8 (critical).
Cesanta Mongoose 6.18 is affected by CVE-2020-25756.
CVE-2020-25756 can be exploited by sending a crafted HTTP header.
Yes, the vulnerability CVE-2020-25756 is disputed, as a committer has stated that it will not happen in practice.