Wolfssl · Wolfssl Wolfmqtt · CVE-2021-45938
Name of the Vulnerable Software and Affected Versions:
wolfSSL wolfMQTT version 1.9
Description:
The issue is a heap-based buffer overflow in the `MqttClient DecodePacket` function, which is called from `MqttClient WaitType` and `MqttClient Unsubscribe`.
Recommendations:
For wolfSSL wolfMQTT version 1.9, consider disabling the `MqttClient DecodePacket` function as a temporary workaround until a patch is available. Restrict access to the `MqttClient WaitType` and `MqttClient Unsubscribe` functions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.