CVE-2011-2900

Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web...

Basic Information

CVE State
PUBLISHED
Reserved Date
July 27, 2011
Published Date
August 05, 2011
Last Updated
August 06, 2024
Vendor
n/a
Product
["Mongoose", "yaSSL Embedded Web Server", "Simple HTTPD"]
Description
Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as exploited in the wild in 2011.

CVSS Scores

CVSS v2.0

7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Exploit Status

Exploited in the Wild
Yes (2011-08-05 21:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2011-08-05 21:00:00 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel