CivetWeb through version 1.10 is vulnerable to an out-of-bounds read in the civetweb.c:send_ssi_file() function. An attacker could exploit this to cause a denial of service or information disclosure via crafted SSI file. Upstream Issue: https://github.com/civetweb/civetweb/issues/633 Upstream Commit: https://github.com/civetweb/civetweb/commit/8fd069f6dedb064339f1091069ac96f3f8bdb552