CVE-2020-13111

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
16/05/2020
Last modified:
21/07/2021

Description

NaviServer 4.99.4 to 4.99.19 allows denial of service due to the nsd/driver.c ChunkedDecode function not properly validating the length of a chunk. A remote attacker can craft a chunked-transfer request that will result in a negative value being passed to memmove via the size parameter, causing the process to crash.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:naviserver_project:naviserver:*:*:*:*:*:*:*:* 4.99.4 (including) 4.99.19 (including)