CVE-2011-2900

High PUBLISHED

Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web...

Mongoose · Mongoose

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
7.5 High

At a Glance

Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as exploited in the wild in 2011.

CVE Published
Aug 05, 2011
Exploitation Reported
Aug 05, 2011
CVSS
7.5 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • FEDORA-2011-11823 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2011-Septem...
  • FEDORA-2011-11825 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2011-Septem...
  • FEDORA-2011-11636 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2011-Septem...
  • 45464 secunia.com · Third-Party Advisory http://secunia.com/advisories/45464
  • 45902 secunia.com · Third-Party Advisory http://secunia.com/advisories/45902
Show 6 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.