First published: Wed Apr 25 2018(Updated: )
In Eclipse Mosquitto 1.4.14, if a Mosquitto instance is set running with a configuration file, then sending a HUP signal to server triggers the configuration to be reloaded from disk. If there are lots of clients connected so that there are no more file descriptors/sockets available (default limit typically 1024 file descriptors on Linux), then opening the configuration file will fail.
Credit: emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Mosquitto | >=1.0<=1.4.14 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
debian/mosquitto | 1.5.7-1+deb10u1 2.0.11-1 2.0.11-1+deb11u1 2.0.11-1.2+deb12u1 2.0.18-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7652 is a vulnerability in Eclipse Mosquitto 1.4.14, where sending a HUP signal to the server triggers the configuration to be reloaded from disk.
The severity of CVE-2017-7652 is high with a severity value of 7.5.
The affected software versions of CVE-2017-7652 include Eclipse Mosquitto 1.0 up to version 1.4.14 and specific versions of the mosquitto package in Debian Linux.
To fix CVE-2017-7652, update to Mosquitto version 1.5.7-1+deb10u1, 2.0.11-1, 2.0.11-1+deb11u1, 2.0.11-1.2+deb12u1, or 2.0.18-1, depending on the Debian Linux version you are using.
More information about CVE-2017-7652 can be found at the following references: [link1], [link2], [link3].