CVE-2024-42390: Use of Out-of-range Pointer Offset in Mongoose Web Server library
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42390?
CVE-2024-42390 is considered a critical vulnerability due to the potential for memory corruption and unauthorized access to heap memory.
How do I fix CVE-2024-42390?
To fix CVE-2024-42390, upgrade the Cesanta Mongoose Web Server to version 7.15 or later, which addresses this vulnerability.
What types of attacks can exploit CVE-2024-42390?
CVE-2024-42390 can be exploited by attackers to send unexpected TLS packets, leading to unintended exposure of heap memory.
Which versions of Cesanta Mongoose are affected by CVE-2024-42390?
CVE-2024-42390 affects Cesanta Mongoose versions up to and including 7.14.
Is CVE-2024-42390 applicable to any other software besides Cesanta Mongoose?
No, CVE-2024-42390 specifically affects the Cesanta Mongoose Web Server and does not apply to other software.