First published: Wed Aug 09 2023(Updated: )
Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version 7.9 and prior does not appear to be vulnerable. This issue is resolved in version 7.11.
Credit: cve@takeonme.org cve@takeonme.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cesanta Mongoose | =7.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2905 is a heap-based buffer overflow vulnerability in Cesanta Mongoose web server version 7.10 and is rated with a severity score of 8.8.
CVE-2023-2905 affects Cesanta Mongoose web server version 7.10 and prior, allowing a heap-based buffer overflow due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header.
CVE-2023-2905 has a severity score of 8.8, which is classified as high.
To fix CVE-2023-2905, upgrade to Cesanta Mongoose version 7.11 or later which includes a fix for the vulnerability.
You can find more information about CVE-2023-2905 on the official CVE website or the GitHub pages related to Cesanta Mongoose.