The Zephyr MQTT parsing code performs insufficient checking of the length field on publish messages, allowing a buffer overflow and potentially remote code execution. NCC-ZEP-031 This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: zephyr
Published:
Updated: 2024-09-17T04:19:36.893Z
Reserved: 2020-03-04T00:00:00
Link: CVE-2020-10071

No data.

Status : Modified
Published: 2020-06-05T18:15:13.087
Modified: 2024-11-21T04:54:44.873
Link: CVE-2020-10071

No data.