A vulnerability was found in mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read. Reference: https://github.com/cesanta/mongoose/pull/1035
Created mongoose tracking bugs for this issue: Affects: epel-6 [bug 1728978] Affects: fedora-all [bug 1728977]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Contrary the description the devs this fix went into 6.15.