CVE-2021-3466 is a critical buffer overflow vulnerability in libmicrohttpd version 0.9.70, affecting products like Fedora and Red Hat Enterprise Linux. A missing bounds check in the post_process_urlencoded function allows remote attackers to write arbitrary data. This flaw carries a CVSS score of 9.8, indicating high impacts on confidentiality, integrity, and availability, with no user interaction required. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion, with 10 mentions across various platforms.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.70CPE matchmatch criteria | cpe:2.3:a:gnu:libmicrohttpd:0.9.70:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.