Vulnerability Description
Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Civetweb Project | Civetweb | <= 1.10 |
Related Weaknesses (CWE)
References
- https://github.com/civetweb/civetweb/commit/8fd069f6dedb064339f1091069ac96f3f8bdPatchThird Party Advisory
- https://github.com/civetweb/civetweb/issues/633Third Party Advisory
- https://github.com/civetweb/civetweb/commit/8fd069f6dedb064339f1091069ac96f3f8bdPatchThird Party Advisory
- https://github.com/civetweb/civetweb/issues/633Third Party Advisory
FAQ
What is CVE-2018-12684?
CVE-2018-12684 is a vulnerability with a CVSS score of 7.1 (HIGH). Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.
How severe is CVE-2018-12684?
CVE-2018-12684 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12684?
Check the references section above for vendor advisories and patch information. Affected products include: Civetweb Project Civetweb.