CVE-2019-5432

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
06/05/2019
Last modified:
03/11/2021

Description

A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mqtt-packet_project:mqtt-packet:*:*:*:*:*:node.js:*:* 3.5.1 (excluding)
cpe:2.3:a:mqtt-packet_project:mqtt-packet:*:*:*:*:*:node.js:*:* 4.0.0 (including) 4.1.3 (including)
cpe:2.3:a:mqtt-packet_project:mqtt-packet:*:*:*:*:*:node.js:*:* 5.0.0 (including) 5.6.1 (including)
cpe:2.3:a:mqtt-packet_project:mqtt-packet:*:*:*:*:*:node.js:*:* 6.0.0 (including) 6.1.2 (including)


References to Advisories, Solutions, and Tools