CVE

CVE-2019-5432

Severity:
HIGH
Type:
CWE-125 Out-of-bounds Read
Publication date:
06/05/2019
Last modified:
03/11/2021

Description

A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions

Vulnerable products and versions

  • cpe:2.3:a:mqtt-packet_project:mqtt-packet:*:*:*:*:*:node.js:*:*
  • cpe:2.3:a:mqtt-packet_project:mqtt-packet:*:*:*:*:*:node.js:*:*
  • cpe:2.3:a:mqtt-packet_project:mqtt-packet:*:*:*:*:*:node.js:*:*
  • cpe:2.3:a:mqtt-packet_project:mqtt-packet:*:*:*:*:*:node.js:*:*

References to Advisories, Solutions, and Tools