A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
2024-02-20T15:15:08.727
2025-02-12T18:50:45.040
Analyzed
CVSSv3.1: 10.0 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | silabs | gecko_software_development_kit | 4.3.2.0 | Yes |
Application | weston-embedded | uc-http | - | Yes |