CVE-2018-12684

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
22/06/2018
Last modified:
10/08/2018

Description

Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:civetweb_project:civetweb:*:*:*:*:*:*:*:* 1.10 (including)