First published: Mon Nov 18 2024(Updated: )
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Credit: prodsec@nozominetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cesanta Mongoose Embedded Web Server Library | <=7.14 |
It is suggested to update the Mongoose Web Server library to v7.15.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42388 is classified as a medium severity vulnerability due to its potential to cause unintended heap memory access.
To fix CVE-2024-42388, update the Cesanta Mongoose Web Server to version 7.15 or later, which addresses the vulnerability.
CVE-2024-42388 affects Cesanta Mongoose Web Server versions up to and including 7.14.
CVE-2024-42388 can be exploited by sending unexpected TLS packets to the server.
Exploitation of CVE-2024-42388 may allow attackers to read unintended heap memory space, leading to sensitive information leakage.