CVE-2024-42384: Integer Overflow or Wraparound in Mongoose Web Server library
Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cesanta Mongoose Web Serverto a version that resolves this vulnerability.Fixed in 7.15
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42384?
The severity of CVE-2024-42384 is considered high due to its potential to cause a segmentation fault.
How do I fix CVE-2024-42384?
To fix CVE-2024-42384, upgrade to Cesanta Mongoose Web Server version 7.15 or later.
What type of vulnerability is CVE-2024-42384?
CVE-2024-42384 is classified as an Integer Overflow or Wraparound vulnerability.
What can an attacker achieve with CVE-2024-42384?
An attacker can send an unexpected TLS packet to trigger a segmentation fault in the application.
Which software versions are affected by CVE-2024-42384?
CVE-2024-42384 affects Cesanta Mongoose Web Server versions up to and including 7.14.