CVE

Id
104005  
CVE No.
CVE-2017-7185  
Status
Candidate  
Description
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary string.  
Phase
Assigned (20170319)  
Votes
None (candidate not yet proposed)  
Comments