CVE-2023-29995: High severity emqx vulnerability
Published May 4, 2023
·Updated
In NanoMQ v0.15.0-0, a Heap overflow occurs in copynutf8str function of mqttparser.c
Affected Software
1 affected component
emqx Nanomq=0.15.0
Event History
May 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
05:15 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-29995?
CVE-2023-29995 has been classified as a high severity vulnerability due to the potential for a heap overflow.
2
How do I fix CVE-2023-29995?
To fix CVE-2023-29995, upgrade to a patched version of NanoMQ that resolves the heap overflow issue.
3
What are the potential impacts of CVE-2023-29995?
The potential impacts of CVE-2023-29995 include application crashes and potential remote code execution.
4
Which version of NanoMQ is affected by CVE-2023-29995?
Only NanoMQ version 0.15.0 is affected by CVE-2023-29995.
5
What function is involved in CVE-2023-29995?
The heap overflow in CVE-2023-29995 occurs in the copyn_utf8_str function of mqtt_parser.c.