First published: Tue Jun 05 2018(Updated: )
The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that do reject invalid UTF-8 strings to disconnect themselves from the broker by sending a topic string which is not valid UTF-8, and so cause a denial of service for the clients.
Credit: emo@eclipse.org emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Mosquitto | <=1.4.15 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
ubuntu/mosquitto | <1.4.15-2ubuntu0.18.04.3 | 1.4.15-2ubuntu0.18.04.3 |
ubuntu/mosquitto | <1.4.15-2ubuntu0.18.10.3 | 1.4.15-2ubuntu0.18.10.3 |
ubuntu/mosquitto | <1.5.4-1 | 1.5.4-1 |
ubuntu/mosquitto | <1.4.8-1ubuntu0.16.04.7 | 1.4.8-1ubuntu0.16.04.7 |
debian/mosquitto | 2.0.11-1+deb11u1 2.0.11-1.2+deb12u1 2.0.18-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7653 is a vulnerability in the Eclipse Mosquitto broker up to version 1.4.15 that allows a malicious client to cause a denial of service by sending a topic string that is not valid UTF-8.
CVE-2017-7653 has a severity rating of 5.3 (medium).
CVE-2017-7653 affects Eclipse Mosquitto broker up to version 1.4.15.
A malicious client can exploit CVE-2017-7653 by sending a topic string that is not valid UTF-8, causing other clients to disconnect from the broker.
Yes, there are remedies available for CVE-2017-7653, such as updating to a fixed version of Eclipse Mosquitto.