CVE-2017-7652: High severity tibco messaging - eclipse mosquitto distribution - core vulnerability
In Eclipse Mosquitto 1.4.14, if a Mosquitto instance is set running with a configuration file, then sending a HUP signal to server triggers the configuration to be reloaded from disk. If there are lots of clients connected so that there are no more file descriptors/sockets available (default limit typically 1024 file descriptors on Linux), then opening the configuration file will fail.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-7652?
CVE-2017-7652 is a vulnerability in Eclipse Mosquitto 1.4.14, where sending a HUP signal to the server triggers the configuration to be reloaded from disk.
What is the severity of CVE-2017-7652?
The severity of CVE-2017-7652 is high with a severity value of 7.5.
Which software versions are affected by CVE-2017-7652?
The affected software versions of CVE-2017-7652 include Eclipse Mosquitto 1.0 up to version 1.4.14 and specific versions of the mosquitto package in Debian Linux.
How can I fix CVE-2017-7652?
To fix CVE-2017-7652, update to Mosquitto version 1.5.7-1+deb10u1, 2.0.11-1, 2.0.11-1+deb11u1, 2.0.11-1.2+deb12u1, or 2.0.18-1, depending on the Debian Linux version you are using.
Where can I find more information about CVE-2017-7652?
More information about CVE-2017-7652 can be found at the following references: [link1], [link2], [link3].