First published: Wed Nov 02 2022(Updated: )
Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.
Credit: product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silabs Micrium Uc-http | =3.01.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24942 is a vulnerability that refers to a heap-based buffer overflow in the HTTP Server functionality in Micrium uC-HTTP 3.01.01, which allows remote code execution via an HTTP request.
CVE-2022-24942 is considered to be a critical vulnerability with a severity rating of 9.8.
The affected software is Silabs Micrium Uc-http version 3.01.01.
CVE-2022-24942 can be exploited by sending a specially crafted HTTP request to the vulnerable server.
You can find more information about CVE-2022-24942 at the following references: [Reference 1](https://community.silabs.com/sfc/servlet.shepherd/document/download/0698Y00000KlMPOQA3?operationContext=S1), [Reference 2](https://github.com/SiliconLabs/gecko_sdk/blame/v4.1.1/platform/micrium_os/net/source/http/server/http_server_req.c).