CVE-2024-42392: Improper Neutralization of Delimiters in Mongoose Web Server library
Published Nov 18, 2024
·Updated
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.
Affected Software
1 affected component
Cesanta Mongoose<=7.14
Remediation
Information
It is suggested to update the Mongoose Web Server library to v7.15.
Event History
Nov 18, 2024
CVE Published
via MITRE·09:07 AM
Data Sourced
via MITRE·09:07 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-42392?
The severity of CVE-2024-42392 is classified as medium due to the potential for triggering an infinite loop bug.
2
How do I fix CVE-2024-42392?
To fix CVE-2024-42392, update Cesanta Mongoose Web Server to version 7.15 or later, which addresses the vulnerability.
3
What systems are affected by CVE-2024-42392?
CVE-2024-42392 affects Cesanta Mongoose Web Server version 7.14 and earlier.
4
What type of vulnerability is CVE-2024-42392?
CVE-2024-42392 is categorized as an Improper Neutralization of Delimiters vulnerability.
5
What can be exploited in CVE-2024-42392?
CVE-2024-42392 can be exploited to trigger an infinite loop if the input string contains unexpected characters.