CVE-2021-33254: Null Pointer Dereference
Published Jun 1, 2022
·Updated
An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramter to the parseUri function.
Affected Software
2 affected components
Embedthis Appweb=8.2.1
Linux Linux kernel
Remediation
Event History
Jun 1, 2022
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-33254.
2
What is the severity of CVE-2021-33254?
CVE-2021-33254 has a severity rating of 7.5 (high).
3
What is the affected software of CVE-2021-33254?
The affected software of CVE-2021-33254 is EmbedThis Appweb Community Edition 8.2.1.
4
How can an attacker exploit CVE-2021-33254?
An attacker can exploit CVE-2021-33254 by sending a malicious stream parameter to the parseUri function in src/http/httpLib.c.
5
Is Linux Linux kernel affected by CVE-2021-33254?
No, Linux Linux kernel is not affected by CVE-2021-33254.