n0o.com - Personal archive of discovered vulns & writeups.

[CVE-2018-12685] Out-of-bounds Read in CivetWeb (2)


Reported on : 2 Jun 2018 Shipped on : 28 Jun 2018 Type : Information Leak In Function : mg_start The libcivetweb must be compiled with Symbian support and runs in Symbian system, then attacker calls the function to get system information locally to trigger this problem. Number of data sources supplied is less than the number declared, which could cause a information leak vunlnerability or Denial of Service.
https://github.com/civetweb/civetweb/issues/633
https://github.com/civetweb/civetweb/commit/6a1f14d47941a190b1c038b67f