An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted Host header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ] character in an IPv6 address.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Appweb | Embedthis | * | 7.0.2 (excluding) |
Goahead | Embedthis | * | 4.0.1 (excluding) |