CVE-2008-2654: Off-by-one error in the read_client function in webhttpd.c in Motion 3 ...

Severity: Critical

CVSS Score: 10

Off-by-one error in the read_client function in webhttpd.c in Motion 3.2.10 and earlier might allow remote attackers to execute arbitrary code via a long request to a Motion HTTP Control interface, which triggers a stack-based buffer overflow with some combinations of processor architecture and compiler.