CVE-2021-34432: Input Validation
In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.
Other sources
In Eclipse Mosquitto versions 2.07 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Eclipse Mosquittoto a version that resolves this vulnerability.Fixed in 2.0.7 - Upgrade
Upgrade
Eclipse Mosquittoto a version that resolves this vulnerability.Fixed in 2.07
Event History
Frequently Asked Questions
What is CVE-2021-34432?
CVE-2021-34432 is a vulnerability in Eclipse Mosquitto versions 2.07 and earlier that can cause the server to crash if the client sends a PUBLISH packet with topic length = 0.
How can CVE-2021-34432 affect me?
If you are using an affected version of Eclipse Mosquitto, an attacker can crash your server by sending a PUBLISH packet with a topic length of 0.
What is the severity of CVE-2021-34432?
CVE-2021-34432 has a severity score of 7.5 out of 10, indicating a high severity vulnerability.
How can I fix CVE-2021-34432?
To fix CVE-2021-34432, you should upgrade to a version of Eclipse Mosquitto that is not affected, such as version 2.0.8 or later.
Where can I find more information about CVE-2021-34432?
You can find more information about CVE-2021-34432 in the official bug report at https://bugs.eclipse.org/bugs/show_bug.cgi?id=574141.