First published: Mon Feb 08 2021(Updated: )
The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after exhausting memory pool.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cesanta Mongoose | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-26528.
The severity of CVE-2021-26528 is critical with a CVSS score of 9.1.
The affected software version is Cesanta Mongoose 7.0.
The CWE ID for this vulnerability is CWE-787.
Yes, you can learn more about this vulnerability at the following link: [GitHub Issue #1201](https://github.com/cesanta/mongoose/issues/1201).