CVE-2017-2894: Buffer Overflow
An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-2894?
CVE-2017-2894 is an exploitable stack buffer overflow vulnerability in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.
How severe is CVE-2017-2894?
CVE-2017-2894 has a severity rating of 9.8, which is considered critical.
How does the vulnerability in CVE-2017-2894 occur?
The vulnerability in CVE-2017-2894 occurs when a specially crafted MQTT SUBSCRIBE packet is sent, causing a stack buffer overflow and leading to remote code execution.
What is the affected software in CVE-2017-2894?
Cesanta Mongoose version 6.8 is the affected software in CVE-2017-2894.
Is there a fix available for CVE-2017-2894?
Yes, it is recommended to update Cesanta Mongoose to a version that is not affected by the vulnerability.