CVE-2017-7185
Cesanta Mongoose OS - Use-After-Free
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary string.
Vulnerabilidad use-after-free en la función mg_http_multipart_wait_for_boundary en mongoose.c en Cesanta Mongoose Embedded Web Server Library 6.7 y anteriores y Mongoose OS 1.2 y anteriores permite a los atacantes remotos provocar una denegación de servicio (caída) a través de un multipart/form-data POST solicitud sin una cadena de límite MIME.
Mongoose OS versions 1.2 and below suffers from use-after-free and denial of service vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-03-19 CVE Reserved
- 2017-04-03 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-10-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-416: Use After Free
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/540355/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/97370 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/41826 | 2024-08-05 | |
https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CVE-2017-7185_mongoose_os_use_after_free.txt | 2024-08-05 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cesanta Search vendor "Cesanta" | Mongoose Embedded Web Server Library Search vendor "Cesanta" for product "Mongoose Embedded Web Server Library" | <= 6.7 Search vendor "Cesanta" for product "Mongoose Embedded Web Server Library" and version " <= 6.7" | - |
Affected
| ||||||
Cesanta Search vendor "Cesanta" | Mongoose Os Search vendor "Cesanta" for product "Mongoose Os" | <= 1.2 Search vendor "Cesanta" for product "Mongoose Os" and version " <= 1.2" | - |
Affected
|