Buffer Overflow in Embedthis GoAhead Web Server Affects HTTP Requests
CVE-2019-19240
5.3MEDIUM
What is CVE-2019-19240?
A vulnerability in Embedthis GoAhead prior to version 5.0.1 allows for improper handling of redirected HTTP requests when encountering an excessively large Host header. The GoAhead WebsRedirect feature has a static buffer with a limited size, which is susceptible to overflow conditions. This situation can lead to the failure of the buffer that holds the Host header, resulting in uninitialized data being included in responses. Consequently, this may expose sensitive information and compromise the integrity of the web server.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved