Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
MQTT-C Heap Out-of-Bounds Read and Integer Underflow in mqtt_unpack_publish_response()
Vulnerability Description
LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or able to inject MQTT traffic into an unencrypted session - to crash a subscribed MQTT-C client and potentially disclose adjacent heap memory by sending a single crafted PUBLISH packet.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Vulnerability Type
跨界内存读
Vulnerability Title
Liam Bindle MQTT-C 缓冲区错误漏洞
Vulnerability Description
Liam Bindle MQTT-C是加拿大Liam Bindle个人开发者的一个用C语言编写的MQTT客户端。 LiamBindle MQTT-C 1.1.6及之前版本存在安全漏洞,该漏洞源于src/mqtt.c中的mqtt_unpack_publish_response()函数存在堆越界读取和整数下溢,可能允许远程未经验证的攻击者通过发送特制的PUBLISH数据包导致订阅的MQTT-C客户端崩溃并可能泄露相邻堆内存。
CVSS Information
N/A
Vulnerability Type
N/A