CVE-2025-66217 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQTT parsing logic of AIS-catcher. This vu…
High CVSS: 8.8

CVE-2025-66217

AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQTT parsing logic of AIS-catcher. This vulnerability allows an attacker to trigger a massive Heap Buffer Overflow by sending a malformed MQTT packet with a manipulated Topic Length field. This leads to an immediate Denial of Service (DoS) and, when used as a library, severe Memory Corruption that can be leveraged for Remote Code Execution (RCE). This issue has been patched in version 0.64.
Vendor
Aiscatcher
Product
Ais-catcher
CWE
CWE-122
Yayın Tarihi
2025-11-29 03:15:59
Güncelleme
2025-12-23 16:10:32
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar