THREAT OPS › Threat News › Paho v1.3.15 Arbitrary Code Execution via Shared Library Search Path Hijacking
Paho v1.3.15 Arbitrary Code Execution via Shared Library Search Path Hijacking
<p>Posted by Ron E on Sep 03</p>*Description:*<br /> Arbitrary code execution is possible in the MQTTVersion utility due to<br /> uncontrolled loading of shared libraries using non-absolute paths. The<br /> application invokes dlopen() with relative library names and relies on the<br /> dynamic loader’s search path to resolve the target library. Because the<br /> library origin is not restricted t
Original source: https://seclists.org/fulldisclosure/2026/Sep/4