uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bounds access to a heap buffer and a subsequent crash. It can be triggered with an HTTP POST request to a CGI script, specifying both "Transfer-Encoding: chunked" and a large negative Content-Length value.
2020-03-16T18:15:12.213
2024-11-21T04:35:42.850
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | openwrt | openwrt | ≤ 18.06.5 | Yes |
Operating System | openwrt | openwrt | 19.07.0 | Yes |
Operating System | openwrt | openwrt | 19.07.0 | Yes |
Operating System | openwrt | openwrt | 19.07.0 | Yes |