CVE-2021-45945

Out-of-bounds Write in conan/uwebsockets

Identifiers

CVE-2021-45945

Package Slug

conan/uwebsockets

Vulnerability

Out-of-bounds Write

Description

uWebSockets has an out-of-bounds write in std::1::pair<unsigned int, void*> uWS::HttpParser::fenceAndConsumePostPadded<0 (called from uWS::HttpParser::consumePostPadded and std::1::function::func<LLVMFuzzerTestOneInput::$0, std::_1::allocator<LL).

Affected Versions

All versions starting from 19.0.0 up to 20.8.0

Solution

Upgrade to version 20.9.0 or above.

Last Modified

2022-01-10

source