A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.
Solution:
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://mattermost.com/security-updates/ | vendor advisory |