CVE-2024-42385: Improper Neutralization of Delimiters in Mongoose Web Server library
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42385?
CVE-2024-42385 has been classified as a high severity vulnerability due to its potential for out-of-bound memory writes.
How do I fix CVE-2024-42385?
To fix CVE-2024-42385, ensure that your Cesanta Mongoose Web Server is upgraded to a version newer than 7.14 that addresses this vulnerability.
What are the potential impacts of CVE-2024-42385?
The potential impacts of CVE-2024-42385 include application crashes and reliance on attacker-supplied PEM certificates leading to memory corruption.
Who is affected by CVE-2024-42385?
CVE-2024-42385 affects users of Cesanta Mongoose Web Server version 7.14 or earlier that utilize PEM certificates.
What is CVE-2024-42385?
CVE-2024-42385 is an improper neutralization of delimiters vulnerability in Cesanta Mongoose Web Server that allows for out-of-bound memory writes.