First published: Mon Nov 18 2024(Updated: )
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Credit: prodsec@nozominetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cesanta Mongoose Embedded Web Server Library | <=7.14 |
It is suggested to update the Mongoose Web Server library to v7.15.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42391 is considered a high-severity vulnerability due to its potential to allow attackers to read unintended heap memory.
To fix CVE-2024-42391, update the Cesanta Mongoose Web Server to version 7.15 or later.
CVE-2024-42391 affects applications that utilize Cesanta Mongoose Web Server version 7.14 and prior.
Exploitation of CVE-2024-42391 may allow attackers to access sensitive information by reading unintended areas of memory.
If unable to update for CVE-2024-42391, it is advisable to restrict access to the web server and monitor for unusual TLS packet traffic.