First published: Mon Nov 18 2024(Updated: )
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Credit: prodsec@nozominetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cesanta Mongoose Embedded Web Server Library | <=7.14 |
It is suggested to update the Mongoose Web Server library to v7.15.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42389 is classified as a high severity vulnerability due to its potential to allow attackers to read unintended heap memory.
To mitigate CVE-2024-42389, upgrade Cesanta Mongoose Web Server to a version higher than 7.14.
CVE-2024-42389 affects Cesanta Mongoose Web Server versions up to and including 7.14.
The impact of CVE-2024-42389 includes potential data leakage and unauthorized access to sensitive information.
Attackers can exploit CVE-2024-42389 by sending unexpected TLS packets to force the application to read unintended memory.