In versions prior to 1.1 of the Eclipse Paho MQTT C Client, the client does not check rem_len size in readpacket.
{ "binaries": [ { "binary_version": "1.3.9-1build1", "binary_name": "libpaho-mqtt-dev" }, { "binary_version": "1.3.9-1build1", "binary_name": "libpaho-mqtt1.3" }, { "binary_version": "1.3.9-1build1", "binary_name": "paho.mqtt.c-examples" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-41036.json"
{ "binaries": [ { "binary_version": "1.3.13-1build2", "binary_name": "libpaho-mqtt-dev" }, { "binary_version": "1.3.13-1build2", "binary_name": "libpaho-mqtt1.3" }, { "binary_version": "1.3.13-1build2", "binary_name": "paho.mqtt.c-examples" } ] }
{ "binaries": [ { "binary_version": "1.3.14-2", "binary_name": "libpaho-mqtt-dev" }, { "binary_version": "1.3.14-2", "binary_name": "libpaho-mqtt1.3" }, { "binary_version": "1.3.14-2", "binary_name": "paho.mqtt.c-examples" } ] }