{"id":"GHSA-g3r2-65gc-qpqc","summary":"Denial of Service in mqtt-packet","details":"Versions of `mqtt-packet` prior to 3.4.6, or 4.x prior to 4.0.5 are affected by a denial of service vulnerability wherein specific sequences of MQTT packets can crash the application.\n\n\n\n\n## Recommendation\n\nVersion 3.x: Update to version 3.4.6 or later.\nVersion 4.x: Update to version 4.0.5 or later.","aliases":["CVE-2016-10523"],"modified":"2023-11-08T03:58:10.418903Z","published":"2019-02-18T23:38:45Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:36:00Z","nvd_published_at":null,"cwe_ids":["CWE-400"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10523"},{"type":"WEB","url":"https://github.com/mcollina/mosca/issues/393"},{"type":"WEB","url":"https://github.com/mqttjs/mqtt-packet/pull/8"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g3r2-65gc-qpqc"},{"type":"WEB","url":"https://www.npmjs.com/advisories/75"}],"affected":[{"package":{"name":"mqtt-packet","ecosystem":"npm","purl":"pkg:npm/mqtt-packet"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.4.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-g3r2-65gc-qpqc/GHSA-g3r2-65gc-qpqc.json"}},{"package":{"name":"mqtt-packet","ecosystem":"npm","purl":"pkg:npm/mqtt-packet"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.0.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-g3r2-65gc-qpqc/GHSA-g3r2-65gc-qpqc.json"}}],"schema_version":"1.9.0"}