9.0.2
10 years ago
7 months ago
Known vulnerabilities in the mqtt-packet package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for freeVulnerability | Vulnerable Version |
---|---|
mqtt-packet is an Encoder and Decoder for MQTT. Affected versions of this package are vulnerable to Buffer Over-read. An attacker could trigger an out of range read on a buffer which throws a How to fix Buffer Over-read? Upgrade | <3.5.1>=4.0.0 <4.1.3>=5.0.0 <5.6.1>=6.0.0 <6.1.2 |
Insufficient validation of MQTT packets allows the attacker to crash the application using a specially crafted packet. | <3.4.6>4.0.0 <4.0.5 |