First published: Mon Nov 18 2024(Updated: )
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.
Credit: prodsec@nozominetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cesanta Mongoose Embedded Web Server Library | <=7.14 |
It is suggested to update the Mongoose Web Server library to v7.15.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42385 has been classified as a high severity vulnerability due to its potential for out-of-bound memory writes.
To fix CVE-2024-42385, ensure that your Cesanta Mongoose Web Server is upgraded to a version newer than 7.14 that addresses this vulnerability.
The potential impacts of CVE-2024-42385 include application crashes and reliance on attacker-supplied PEM certificates leading to memory corruption.
CVE-2024-42385 affects users of Cesanta Mongoose Web Server version 7.14 or earlier that utilize PEM certificates.
CVE-2024-42385 is an improper neutralization of delimiters vulnerability in Cesanta Mongoose Web Server that allows for out-of-bound memory writes.