Buffer Overflow Vulnerability in libmicrohttpd Affects Multiple Systems
CVE-2021-3466
9.8CRITICAL
What is CVE-2021-3466?
A vulnerability has been identified in libmicrohttpd where a missing bounds check in the post_process_urlencoded function results in a buffer overflow. This flaw can be exploited by a remote attacker to inject arbitrary data into applications utilizing libmicrohttpd, potentially compromising data confidentiality and integrity. Furthermore, the flaw threatens system availability, allowing exploitation that can disrupt service functionality. The only affected version is 0.9.70, making it essential for users and administrators to review their deployments and implement necessary updates.
Affected Version(s)
libmicrohttpd libmicrohttpd 0.9.70