cesanta.mongoose is vulnerable to Out-of-bounds Read
65
Medium Risk
The built-in TCP/IP stack parses chained IPv6 extension headers in a loop that only validates the total offset after the loop finishes. Crafted extension headers advance the parse pointer past the validated payload, reading adjacent heap memory on each iteration. An unauthenticated peer on the local segment can crash the device or use the over-read values as a side channel. The fix bounds the pointer on every iteration.
You are affected if you are using a version that falls within the vulnerable range and you enable the built-in TCP/IP stack (MG_ENABLE_TCPIP) with IPv6.
cesanta.mongoose is vulnerable to Out-of-bounds Read in versions 7.20 - 7.21.
Upgrade the cesanta.mongoose library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant