First published: Mon Nov 18 2024(Updated: )
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
Credit: prodsec@nozominetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cesanta Mongoose Embedded Web Server Library | <=7.14 |
It is suggested to update the Mongoose Web Server library to v7.15.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42386 is classified as a critical vulnerability due to its potential to cause application crashes and denial of service.
To mitigate CVE-2024-42386, upgrade Cesanta Mongoose Web Server to version 7.15 or later immediately.
CVE-2024-42386 is categorized as an out-of-range pointer offset vulnerability.
Attackers can exploit CVE-2024-42386 to send unexpected TLS packets, leading to segmentation faults.
CVE-2024-42386 affects Cesanta Mongoose Web Server versions up to and including 7.14.