Vulnerability Description
In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a memory leak. Processing of a single crafted packet leads to leaking (wasting) 24 bytes of memory. This can lead to termination of the LWM2M server after exhausting all available memory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Wakaama | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/eclipse/wakaama/issues/425ExploitIssue TrackingPatch
- https://github.com/eclipse/wakaama/issues/425ExploitIssue TrackingPatch
FAQ
What is CVE-2019-9004?
CVE-2019-9004 is a vulnerability with a CVSS score of 7.5 (HIGH). In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a memory leak. Processing of a single crafted packet ...
How severe is CVE-2019-9004?
CVE-2019-9004 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-9004?
Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Wakaama.