CVE-2021-45932: Buffer Overflow
Published Dec 31, 2021
·Updated
wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow (4 bytes) in MqttDecodePublish (called from MqttClientDecodePacket and MqttClientHandlePacket).
Affected Software
1 affected component
wolfSSL wolfMQTT=1.9
Remediation
Event History
Dec 31, 2021
CVE Published
via MITRE·11:58 PM
Data Sourced
via MITRE·11:58 PM
Description
Jan 1, 2022
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-45932?
CVE-2021-45932 is a vulnerability in wolfSSL wolfMQTT 1.9 that allows a heap-based buffer overflow, resulting in potential code execution or denial of service.
2
How severe is CVE-2021-45932?
CVE-2021-45932 has a severity score of 5.5, which is considered medium.
3
What is the affected software version of CVE-2021-45932?
The affected software version of CVE-2021-45932 is wolfSSL wolfMQTT 1.9.
4
How can CVE-2021-45932 be exploited?
CVE-2021-45932 can be exploited by sending a specially crafted MQTT packet that triggers the heap-based buffer overflow.
5
Is there a fix for CVE-2021-45932?
Yes, a fix for CVE-2021-45932 is available in the latest version of wolfSSL wolfMQTT. It is recommended to update to the latest version to mitigate the vulnerability.