CVE-2024-42391: Use of Out-of-range Pointer Offset in Mongoose Web Server library
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42391?
CVE-2024-42391 is considered a high-severity vulnerability due to its potential to allow attackers to read unintended heap memory.
How do I fix CVE-2024-42391?
To fix CVE-2024-42391, update the Cesanta Mongoose Web Server to version 7.15 or later.
What types of applications are affected by CVE-2024-42391?
CVE-2024-42391 affects applications that utilize Cesanta Mongoose Web Server version 7.14 and prior.
What happens if I am exploited by CVE-2024-42391?
Exploitation of CVE-2024-42391 may allow attackers to access sensitive information by reading unintended areas of memory.
Is there a workaround for CVE-2024-42391 if I cannot update?
If unable to update for CVE-2024-42391, it is advisable to restrict access to the web server and monitor for unusual TLS packet traffic.