First published: Mon Feb 08 2021(Updated: )
The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cesanta Mongoose | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26530 is a vulnerability in the mg_tls_init function of Cesanta Mongoose HTTPS server 7.0 that allows remote OOB write attacks after exhausting the memory pool.
The vulnerability affects Cesanta Mongoose HTTPS server 7.0 compiled with OpenSSL support.
CVE-2021-26530 has a severity rating of 9.1 out of 10, making it critical.
To fix CVE-2021-26530, it is recommended to update to a version of Cesanta Mongoose HTTPS server that is not affected by the vulnerability.
Yes, you can find more information about CVE-2021-26530 at the following reference: https://github.com/cesanta/mongoose/issues/1204