CVE-2023-34494: Use After Free
Published Jun 12, 2023
·Updated
NanoMQ 0.16.5 is vulnerable to heap-use-after-free in the nanoctxsend function of nmqmqtt.c.
Affected Software
1 affected component
emqx Nanomq=0.16.5
Remediation
Patch Available
Event History
Jun 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-34494?
CVE-2023-34494 has been categorized with a high severity due to the potential exploitation of a heap-use-after-free vulnerability.
2
How do I fix CVE-2023-34494?
To remediate CVE-2023-34494, you should upgrade NanoMQ to version 0.16.6 or later where the vulnerability is addressed.
3
What systems are affected by CVE-2023-34494?
CVE-2023-34494 affects NanoMQ version 0.16.5 specifically.
4
What complications can result from exploiting CVE-2023-34494?
Exploiting CVE-2023-34494 can lead to remote code execution or application crashes.
5
Who discovered CVE-2023-34494?
CVE-2023-34494 was reported through community contributions, with discussions ongoing on platforms like GitHub.