CVE-2021-45933: Buffer Overflow
Published Dec 31, 2021
·Updated
wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow (8 bytes) in MqttDecodePublish (called from MqttClientDecodePacket and MqttClientHandlePacket).
Affected Software
1 affected component
wolfSSL wolfMQTT=1.9
Remediation
Event History
Dec 31, 2021
CVE Published
via MITRE·11:58 PM
Data Sourced
via MITRE·11:58 PM
Description
Jan 1, 2022
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-45933?
The severity of CVE-2021-45933 is medium.
2
What is the affected software of CVE-2021-45933?
The affected software of CVE-2021-45933 is wolfSSL wolfMQTT 1.9.
3
How can I fix CVE-2021-45933?
To fix CVE-2021-45933, update your wolfSSL wolfMQTT version to the latest release.
4
What is the CWE ID of CVE-2021-45933?
The CWE ID of CVE-2021-45933 is CWE-119 and CWE-787.
5
Where can I find more information about CVE-2021-45933?
You can find more information about CVE-2021-45933 at the following references: [link1](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=38237), [link2](https://github.com/google/oss-fuzz-vulns/blob/main/vulns/wolfmqtt/OSV-2021-1211.yaml), [link3](https://github.com/wolfSSL/wolfMQTT/commit/84d4b53122e0fa0280c7872350b89d5777dabbb2).