PT-2020-16185 · Cesanta · Mongoose

·

CVE-2020-25756

·

Published

2020-09-18

·

Updated

2024-08-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cesanta Mongoose version 6.18
Description A buffer overflow issue exists in the mg get http header function due to a lack of bounds checking, which can be exploited by a crafted HTTP header.
Recommendations For Cesanta Mongoose version 6.18, consider applying bounds checking to the mg get http header function to prevent buffer overflow exploitation. As a temporary workaround, restrict the use of crafted HTTP headers until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25756

Affected Products

Mongoose