A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nmq_subinfo_decode() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack.
References
Link | Resource |
---|---|
https://github.com/emqx/nanomq | Product |
https://github.com/emqx/nanomq/issues/1154 | Exploit Issue Tracking Third Party Advisory |
https://github.com/nanomq/NanoNNG/pull/509/commits/6815c4036a2344865da393803ecdb7af27d8bde1 | Patch |
Configurations
History
No history.
Information
Published : 2023-06-06 12:15
Updated : 2023-06-15 12:21
NVD link : CVE-2023-33659
Mitre link : CVE-2023-33659
CVE.ORG link : CVE-2023-33659
JSON object : View
Products Affected
emqx
- nanomq
CWE
CWE-787
Out-of-bounds Write