CVE-2021-45939

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_WaitType and MqttClient_Subscribe).
Configurations

Configuration 1 (hide)

cpe:2.3:a:wolfssl:wolfmqtt:1.9:*:*:*:*:*:*:*

History

11 Jan 2022, 21:22

Type Values Removed Values Added
CPE cpe:2.3:a:wolfssl:wolfmqtt:1.9:*:*:*:*:*:*:*
First Time Wolfssl
Wolfssl wolfmqtt
References (MISC) https://github.com/wolfSSL/wolfMQTT/commit/84d4b53122e0fa0280c7872350b89d5777dabbb2 - (MISC) https://github.com/wolfSSL/wolfMQTT/commit/84d4b53122e0fa0280c7872350b89d5777dabbb2 - Patch, Third Party Advisory
References (MISC) https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=39103 - (MISC) https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=39103 - Exploit, Issue Tracking, Third Party Advisory
References (MISC) https://github.com/google/oss-fuzz-vulns/blob/main/vulns/wolfmqtt/OSV-2021-1361.yaml - (MISC) https://github.com/google/oss-fuzz-vulns/blob/main/vulns/wolfmqtt/OSV-2021-1361.yaml - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 5.5
CWE CWE-787

01 Jan 2022, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-01 01:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-45939

Mitre link : CVE-2021-45939

CVE.ORG link : CVE-2021-45939


JSON object : View

Products Affected

wolfssl

  • wolfmqtt
CWE
CWE-787

Out-of-bounds Write