Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a GET %n://localhost:80/ request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mbedthis_appweb_http_server | Mbedthis_software | 2.0.5-4 (including) | 2.0.5-4 (including) |