Remote Out-of-Bound Write Vulnerability in Cesanta Mongoose HTTPS Server
CVE-2021-26529
9.1CRITICAL
What is CVE-2021-26529?
The mg_tls_init function in Cesanta's Mongoose HTTPS Server (versions 6.7 to 7.0) contains a vulnerability that can be exploited through a remote out-of-bound write attack. This occurs when a connection request is processed after the server's memory pool has been exhausted. Such exploitation could potentially lead to unauthorized access or manipulation of the server's memory space, highlighting the importance of timely updates and secure coding practices.
