CVE-2023-2905: Cesanta Mongoose MQTT Message Parsing Heap Overflow
Due to a failure in validating the length of a provided MQTTCMDPUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version 7.9 and prior does not appear to be vulnerable. This issue is resolved in version 7.11.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-2905?
CVE-2023-2905 is a heap-based buffer overflow vulnerability in Cesanta Mongoose web server version 7.10 and is rated with a severity score of 8.8.
How does CVE-2023-2905 affect Cesanta Mongoose?
CVE-2023-2905 affects Cesanta Mongoose web server version 7.10 and prior, allowing a heap-based buffer overflow due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header.
What is the severity of CVE-2023-2905?
CVE-2023-2905 has a severity score of 8.8, which is classified as high.
How can I fix CVE-2023-2905?
To fix CVE-2023-2905, upgrade to Cesanta Mongoose version 7.11 or later which includes a fix for the vulnerability.
Where can I find more information about CVE-2023-2905?
You can find more information about CVE-2023-2905 on the official CVE website or the GitHub pages related to Cesanta Mongoose.