In this particular vulnerability, a buffer overflow of 1 byte occurs when handling the header fields in an HTTP request. This just one-byte overflow is important because the µC/HTTP-server heap implementation suppliers a pointer into a free of charge chunk of memory in the initial four bytes of the allocation. Therefore the one byte overwrite can