{ "schema_version": "1.4.0", "id": "GHSA-r945-w37w-79vf", "modified": "2025-04-20T03:35:44Z", "published": "2022-05-14T02:45:52Z", "aliases": [ "CVE-2017-7185" ], "details": "Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary string.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-7185" }, { "type": "WEB", "url": "https://github.com/cesanta/mongoose-os/commit/042eb437973a202d00589b13d628181c6de5cf5b" }, { "type": "WEB", "url": "https://github.com/cesanta/mongoose/commit/b8402ed0733e3f244588b61ad5fedd093e3cf9cc" }, { "type": "WEB", "url": "https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CVE-2017-7185_mongoose_os_use_after_free.txt" }, { "type": "WEB", "url": "https://www.exploit-db.com/exploits/41826" }, { "type": "WEB", "url": "http://www.securityfocus.com/archive/1/540355/100/0/threaded" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/97370" } ], "database_specific": { "cwe_ids": [ "CWE-416" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2017-04-10T15:59:00Z" } }