CVE-2019-9004: High severity eclipse wakaama vulnerability
In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a memory leak. Processing of a single crafted packet leads to leaking (wasting) 24 bytes of memory. This can lead to termination of the LWM2M server after exhausting all available memory.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-9004?
CVE-2019-9004 is a vulnerability in Eclipse Wakaama (formerly liblwm2m) 1.0 that leads to a memory leak due to mishandling of invalid options.
What is the severity of CVE-2019-9004?
CVE-2019-9004 has a severity rating of 7.5, which is considered high.
How does CVE-2019-9004 affect Eclipse Wakaama?
CVE-2019-9004 affects Eclipse Wakaama 1.0 by causing a memory leak when processing a crafted packet with invalid options.
How can I fix CVE-2019-9004 in Eclipse Wakaama?
To fix CVE-2019-9004 in Eclipse Wakaama, it is recommended to update to the latest version or apply the patch provided by the vendor.
Where can I find more information about CVE-2019-9004?
More information about CVE-2019-9004 can be found at the following link: [https://github.com/eclipse/wakaama/issues/425]