CVE-2024-42384: Integer Overflow or Wraparound in Mongoose Web Server library
Published Nov 18, 2024
·Updated
Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
Affected Software
1 affected component
Cesanta Mongoose<=7.14
Remediation
Information
It is suggested to update the Mongoose Web Server library to v7.15.
Event History
Nov 18, 2024
CVE Published
via MITRE·09:04 AM
Data Sourced
via MITRE·09:04 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42384?
The severity of CVE-2024-42384 is considered high due to its potential to cause a segmentation fault.
2
How do I fix CVE-2024-42384?
To fix CVE-2024-42384, upgrade to Cesanta Mongoose Web Server version 7.15 or later.
3
What type of vulnerability is CVE-2024-42384?
CVE-2024-42384 is classified as an Integer Overflow or Wraparound vulnerability.
4
What can an attacker achieve with CVE-2024-42384?
An attacker can send an unexpected TLS packet to trigger a segmentation fault in the application.
5
Which software versions are affected by CVE-2024-42384?
CVE-2024-42384 affects Cesanta Mongoose Web Server versions up to and including 7.14.