Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.802139
Category:Web Servers
Title:Mongoose Web Server Remote Buffer Overflow Vulnerability
Summary:Mongoose Web Server is prone to a remote buffer overflow; vulnerability.
Description:Summary:
Mongoose Web Server is prone to a remote buffer overflow
vulnerability.

Vulnerability Insight:
The flaw is due to an error in the 'put_dir()' function
(mongoose.c) when processing HTTP PUT web requests. This can be exploited to cause an assertion
error or a stack-based buffer overflow.

Vulnerability Impact:
Successful exploitation will allow remote attackers to execute
arbitrary code within the context of the affected application. Failed exploit attempts will
result in a denial-of-service condition.

Affected Software/OS:
Mongoose Web Server version 3.0.

Solution:
Apply the patch from the referenced advisory.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-2900
45464
http://secunia.com/advisories/45464
45902
http://secunia.com/advisories/45902
48980
http://www.securityfocus.com/bid/48980
8337
http://securityreason.com/securityalert/8337
FEDORA-2011-11636
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065273.html
FEDORA-2011-11823
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065505.html
FEDORA-2011-11825
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065537.html
[oss-security] 20110803 CVE id request: shttpd/mongoose/yassl embedded webserver
http://www.openwall.com/lists/oss-security/2011/08/03/5
[oss-security] 20110803 Re: CVE id request: shttpd/mongoose/yassl embedded webserver
http://www.openwall.com/lists/oss-security/2011/08/03/9
https://code.google.com/p/mongoose/source/detail?r=556f4de91eae4bac40dc5d4ddbd9ec7c424711d0
mongoose-put-bo(68991)
https://exchange.xforce.ibmcloud.com/vulnerabilities/68991
CopyrightCopyright (C) 2011 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.