CVE-2021-26530

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
08/02/2021
Last modified:
12/02/2021

Description

The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cesanta:mongoose:7.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools