Improper Neutralization of Delimiters
CVE-2024-42385
Summary
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.
- HIGH
- LOCAL
- NONE
- UNCHANGED
- REQUIRED
- HIGH
- NONE
- HIGH
CWE-140 - Improper Neutralization of Delimiters
The software does not neutralize or incorrectly neutralizes delimiters.
References
Advisory Timeline
- Published