CVE-2020-25756

NameCVE-2020-25756
Description** DISPUTED ** A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking. A crafted HTTP header can exploit this bug. NOTE: a committer has stated "this will not happen in practice."
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh

Notes

NOT-FOR-US: Cesanta Mongoose
smplayer embeds a copy, which is unused in any released version and disabled since 18.5.0~ds1-1

Search for package or bug name: Reporting problems