9.8
CVSSv3

CVE-2017-2891

Published: 07/11/2017 Updated: 07/06/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution. An attacker needs to send this HTTP request over the network to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cesanta mongoose 6.8

Vendor Advisories

Debian Bug report logs - #898943 Multiple vulnerabiliities in Mongoose Package: src:smplayer; Maintainer for src:smplayer is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 17 May 2018 16:51:02 UTC Severity: grave Tags: security Fixed in ...