PT-2025-48360 · Unknown · Ais-Catcher
Jaenact
·
Publicado
2025-11-29
·
Atualizado
2025-12-01
·
CVE-2025-66217
CVSS v4.0
8.8
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AIS-catcher versions prior to 0.64
Description
AIS-catcher, a multi-platform AIS receiver, contains a flaw in its MQTT parsing logic. An integer underflow can be triggered by sending a crafted MQTT packet with a modified Topic Length field. This can cause a significant Heap Buffer Overflow, resulting in a Denial of Service (DoS). When used as a library, this can also lead to severe Memory Corruption, potentially enabling Remote Code Execution (RCE). The issue is related to the parsing of the
Topic Length field within MQTT packets.Recommendations
Update to version 0.64 or later.
Exploit
Correção
RCE
DoS
Integer Underflow
Heap Based Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ais-Catcher