cesanta.mongoose is vulnerable to Out-of-bounds Read
55
Medium Risk
The built-in TCP/IP stack's TCP option handler checks for a zero-length option but not for an option whose declared length exceeds the remaining option bytes. A crafted SYN with a padded MSS option reads one byte past the option area, and that byte becomes the connection's maximum segment size. When the stray byte is zero, the connection silently transmits no application data while appearing healthy. The fix rejects options longer than the remaining bytes.
You are affected if you are using a version that falls within the vulnerable range and you enable the built-in TCP/IP stack (MG_ENABLE_TCPIP).
cesanta.mongoose is vulnerable to Out-of-bounds Read in versions 7.18 - 7.22.
Upgrade the cesanta.mongoose library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant