PT-2024-38981 · Eclipse+3 · Eclipse Mosquitto+3
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Eclipse Mosquitto versions up to 2.0.18a
Description:
The issue allows an attacker to cause memory leaking, segmentation fault, or heap-use-after-free by sending specific sequences of packets, including "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE", and "PUBLISH" packets.
Recommendations:
For Eclipse Mosquitto versions up to 2.0.18a, consider restricting the handling of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE", and "PUBLISH" packets until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Improper Handling of Exceptional Conditions
Memory Leak
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Eclipse Mosquitto
Red Os