VYPR
Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Oct 10, 2024

Cesanta Mongoose MQTT Message Parsing Heap Overflow

CVE-2023-2905

Description

Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version 7.9 and prior does not appear to be vulnerable. This issue is resolved in version 7.11.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Cesanta/Mongoosellm-fuzzy2 versions
    =7.10+ 1 more
    • (no CPE)range: =7.10
    • (no CPE)range: 7.10

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.