CVE-2020-25756: Buffer Overflow
Published Sep 18, 2020
·Updated
DISPUTED A buffer overflow vulnerability exists in the mggethttpheader function in Cesanta Mongoose 6.18 due to a lack of bounds checking. A crafted HTTP header can exploit this bug. NOTE: a committer has stated "this will not happen in practice."
Affected Software
1 affected component
Cesanta Mongoose=6.18
Remediation
Patch Available
Event History
Sep 18, 2020
CVE Published
via MITRE·04:44 AM
Data Sourced
via MITRE·04:44 AM
Description
Disputed
05:15 AM
Frequently Asked Questions
1
What is CVE-2020-25756?
CVE-2020-25756 is a buffer overflow vulnerability in the mg_get_http_header function in Cesanta Mongoose 6.18.
2
How severe is CVE-2020-25756?
CVE-2020-25756 has a severity rating of 9.8 (critical).
3
Which software is affected by CVE-2020-25756?
Cesanta Mongoose 6.18 is affected by CVE-2020-25756.
4
How can CVE-2020-25756 be exploited?
CVE-2020-25756 can be exploited by sending a crafted HTTP header.
5
Is the vulnerability CVE-2020-25756 disputed?
Yes, the vulnerability CVE-2020-25756 is disputed, as a committer has stated that it will not happen in practice.