Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Oct 10, 2024
Cesanta Mongoose MQTT Message Parsing Heap Overflow
CVE-2023-2905
Description
Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version 7.9 and prior does not appear to be vulnerable. This issue is resolved in version 7.11.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/cesanta/mongoose/pull/2274mitrepatch
- takeonme.org/cves/CVE-2023-2905.htmlmitrethird-party-advisorytechnical-descriptionexploit
- github.com/cesanta/mongoose/releases/tag/7.11mitrerelease-notes
News mentions
0No linked articles in our index yet.