Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-20356

Опубликовано: 10 июн. 2019
Источник: debian
EPSS Низкий

Описание

An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

Примечания

  • Historic bug report against Cesanta Mongoose

  • smplayer embeds a copy, which is unused in any released version and disabled since 18.5.0~ds1-1

EPSS

Процентиль: 88%
0.03574
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
около 7 лет назад

An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

CVSS3: 9.8
github
около 4 лет назад

An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

EPSS

Процентиль: 88%
0.03574
Низкий