Описание
Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthenticated attacker can send a single crafted ClientHello with an oversized session id length to read past the receive buffer, crashing any HTTPS, MQTTS, or WSS service built on MG_TLS_BUILTIN.
A flaw was found in Mongoose. An out-of-bounds read vulnerability exists in the built-in TLS server function mg_tls_server_recv_hello(). A remote, unauthenticated attacker can exploit this by sending a specially crafted TLS ClientHello message with an oversized session ID length. This can lead to reading past the receive buffer, causing a denial of service (DoS) by crashing any HTTPS, MQTTS, or WSS service utilizing MG_TLS_BUILTIN.
Отчет
An out-of-bounds read vulnerability was found in Cesanta Mongoose's built-in TLS server implementation (MG_TLS_BUILTIN). A remote, unauthenticated attacker can crash any HTTPS, MQTTS, or WSS service by sending a crafted TLS ClientHello message with an oversized session ID length. This flaw only affects deployments using Mongoose before 7.22 built-in TLS stack; services configured to use external TLS libraries (such as OpenSSL) are not vulnerable to this issue.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Ссылки на источники
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthenticated attacker can send a single crafted ClientHello with an oversized session id length to read past the receive buffer, crashing any HTTPS, MQTTS, or WSS service built on MG_TLS_BUILTIN.
Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthenticated attacker can send a single crafted ClientHello with an oversized session id length to read past the receive buffer, crashing any HTTPS, MQTTS, or WSS service built on MG_TLS_BUILTIN.
Cesanta Mongoose before 7.22 contains an out-of-bounds read in the bui ...
Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthenticated attacker can send a single crafted ClientHello with an oversized session id length to read past the receive buffer, crashing any HTTPS, MQTTS, or WSS service built on MG_TLS_BUILTIN.
7.5 High
CVSS3