PT-2019-17447 · Blynk · Blynk-Library

Lilith Wyatt

·

Published

2019-09-05

·

Updated

2022-06-27

·

CVE-2019-5065

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Blynk-Library version 0.6.1
Description An information disclosure issue exists in the packet-parsing functionality. A specially crafted packet can cause an unterminated strncpy, resulting in information disclosure. An attacker can send a packet to trigger this issue.
Recommendations For Blynk-Library version 0.6.1, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-5065

Affected Products

Blynk-Library