A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibly execute arbitrary code.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://treck.com/vulnerability-response-information/ | vendor advisory |
https://security.netapp.com/advisory/ntap-20210201-0003/ | third party advisory |