CVE-2016-10523
Denial of Service in mqtt-packet
EPSS 0.38%
描述
Versions of `mqtt-packet` prior to 3.4.6, or 4.x prior to 4.0.5 are affected by a denial of service vulnerability wherein specific sequences of MQTT packets can crash the application. ## Recommendation Version 3.x: Update to version 3.4.6 or later. Version 4.x: Update to version 4.0.5 or later.
如何修補 CVE-2016-10523
要修補 CVE-2016-10523,請將受影響套件升級到下列已修補版本。
- npm/mqtt-packet—升級至 3.4.6 或更新版本
CVE-2016-10523 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 3.4.6