VDB

CVE-2021-3466

CVE-2021-3466 PUBLISHED CVSS 10 CRITICAL

A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Only version 0.9.70 is vulnerable.

EPSS 0.42% · 62.3th percentile

Risk Scores

CVSS 2.0
10
EPSS Score
0.42%
62.3th percentile

Affected Products

VendorProductVersions
redhatenterprise_linux7.0, 8.0, 6.0
fedoraprojectfedora32, 33, 34
n/alibmicrohttpd*
gnulibmicrohttpd0.9.70

Timeline

  • Mar 25, 2021 CVE Published
  • Apr 14, 2021 EPSS Score
  • May 5, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›