Buffer Overflow in Embedthis GoAhead Web Server Affects HTTP Requests
CVE-2019-19240

5.3MEDIUM

Key Information:

Vendor

Embedthis

Status
Vendor
CVE Published:
22 November 2019

What is CVE-2019-19240?

A vulnerability in Embedthis GoAhead prior to version 5.0.1 allows for improper handling of redirected HTTP requests when encountering an excessively large Host header. The GoAhead WebsRedirect feature has a static buffer with a limited size, which is susceptible to overflow conditions. This situation can lead to the failure of the buffer that holds the Host header, resulting in uninitialized data being included in responses. Consequently, this may expose sensitive information and compromise the integrity of the web server.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.