cesanta.mongoose is vulnerable to Out-of-bounds Read
78
High Risk
The built-in TLS certificate-chain parser reads per-certificate sizes from a handshake message without validating them against the received record length. An attacker-controlled size drives a heap out-of-bounds read of up to sixteen megabytes during the handshake. A malicious server, or a client under mutual TLS, can disclose adjacent heap memory such as keys and tokens or crash the process, without authentication. The fix bounds each certificate size against the available data.
You are affected if you are using a version that falls within the vulnerable range and you use the built-in TLS backend (MG_TLS_BUILTIN) and parse a peer certificate chain.
cesanta.mongoose is vulnerable to Out-of-bounds Read in versions 7.17 - 7.21.
Upgrade the cesanta.mongoose library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant