CVE-2021-27425: Cesanta Software Mongoose-OS Integer Overflow or Wraparound
Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mmmalloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-27425?
CVE-2021-27425 is a vulnerability in Cesanta Software Mongoose-OS v2.17.0 that allows for integer wrap-around in the function mm_malloc, leading to arbitrary memory allocation and potential remote code injection/execution.
How severe is CVE-2021-27425?
CVE-2021-27425 has a severity rating of 9.8, which is considered critical.
How can the CVE-2021-27425 vulnerability be exploited?
The CVE-2021-27425 vulnerability can be exploited by triggering the integer wrap-around in the mm_malloc function, allowing for arbitrary memory allocation and potential remote code injection or execution.
What software versions are affected by CVE-2021-27425?
CVE-2021-27425 affects Mongoose-OS version 2.17.0.
Are there any mitigations for CVE-2021-27425?
Currently, there are no known mitigations for CVE-2021-27425. It is recommended to update to a patched version of Mongoose-OS when available.