CVE-2019-5065: Medium severity blynk vulnerability
An exploitable information disclosure vulnerability exists in the packet-parsing functionality of Blynk-Library v0.6.1. A specially crafted packet can cause an unterminated strncpy, resulting in information disclosure. An attacker can send a packet to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5065?
CVE-2019-5065 has been classified as a medium severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2019-5065?
To mitigate CVE-2019-5065, upgrade Blynk-Library to a version that addresses this vulnerability.
What type of attack does CVE-2019-5065 allow?
CVE-2019-5065 allows an attacker to send specially crafted packets that can lead to information disclosure.
Which version of Blynk-Library is affected by CVE-2019-5065?
CVE-2019-5065 specifically affects Blynk-Library version 0.6.1.
How can I determine if my application is vulnerable to CVE-2019-5065?
To determine if your application is vulnerable, check if it is using Blynk-Library version 0.6.1 and review the packet-parsing functionality for any insecure handling.