CVE-2023-51771

In MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer overflow via a long URI.
Configurations

Configuration 1 (hide)

cpe:2.3:a:starnight:micro_http_server:-:*:*:*:*:*:*:*

History

03 Jan 2024, 21:02

Type Values Removed Values Added
CWE CWE-120
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:starnight:micro_http_server:-:*:*:*:*:*:*:*
First Time Starnight micro Http Server
Starnight
References () https://github.com/starnight/MicroHttpServer/issues/8 - () https://github.com/starnight/MicroHttpServer/issues/8 - Exploit, Issue Tracking
References () https://github.com/starnight/MicroHttpServer/tree/a8ab029c9a26a4c9f26b9d8a2757b8299aaff120 - () https://github.com/starnight/MicroHttpServer/tree/a8ab029c9a26a4c9f26b9d8a2757b8299aaff120 - Product

26 Dec 2023, 20:34

Type Values Removed Values Added
Summary
  • (es) En MicroHttpServer (también conocido como Micro HTTP Server) hasta a8ab029, _ParseHeader en lib/server.c permite un desbordamiento de búfer de recepción de un byte a través de un URI largo.

25 Dec 2023, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-25 05:15

Updated : 2024-01-03 21:02


NVD link : CVE-2023-51771

Mitre link : CVE-2023-51771

CVE.ORG link : CVE-2023-51771


JSON object : View

Products Affected

starnight

  • micro_http_server
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')