webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request that contains a negative integer in the Content-Length header.
| Software | From | Fixed in |
|---|---|---|
| goahead / goahead_webserver | 2.0 | 2.0.x |
| goahead / goahead_webserver | 2.1.2 | 2.1.2.x |
| goahead / goahead_webserver | 2.1.1 | 2.1.1.x |
| goahead / goahead_webserver | 2.1 | 2.1.x |
| goahead / goahead_webserver | - | 2.1.3.x |