CVE-2023-29994: High severity emqx vulnerability
Published May 4, 2023
·Updated
In NanoMQ v0.15.0-0, Heap overflow occurs in readbyte function of mqttcode.c.
Affected Software
1 affected component
emqx Nanomq=0.15.0
Event History
May 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
05:15 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-29994?
CVE-2023-29994 has been classified with a high severity rating due to the potential for a heap overflow which can lead to code execution.
2
How do I fix CVE-2023-29994?
To fix CVE-2023-29994, upgrade to a version of NanoMQ that is newer than v0.15.0, which contains the necessary patches.
3
What are the potential impacts of CVE-2023-29994?
The potential impacts of CVE-2023-29994 include arbitrary code execution and potential denial of service if exploited by an attacker.
4
Which software versions are affected by CVE-2023-29994?
CVE-2023-29994 specifically affects NanoMQ version 0.15.0.
5
Where can I find more information about CVE-2023-29994?
Additional information about CVE-2023-29994 can typically be found in vulnerability databases and issue tracking systems related to NanoMQ.