First published: Fri Sep 01 2023(Updated: )
In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets.
Credit: emo@eclipse.org emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mosquitto | <=2.0.11-1<=2.0.11-1.2 | 1.5.7-1+deb10u1 2.0.11-1+deb11u1 2.0.11-1.2+deb12u1 2.0.18-1 |
Eclipse Mosquitto | <2.0.16 | |
redhat/mosquitto | <2.0.16 | 2.0.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0809 is a vulnerability in Mosquitto before 2.0.16 that allows for excessive memory allocation based on malicious initial packets.
CVE-2023-0809 affects Mosquitto versions before 2.0.16.
CVE-2023-0809 has a severity score of 5.8, which is considered medium.
To fix CVE-2023-0809, update Mosquitto to version 2.0.16 or later.
You can find more information about CVE-2023-0809 in the references provided: [https://mosquitto.org/blog/2023/08/version-2-0-16-released/](https://mosquitto.org/blog/2023/08/version-2-0-16-released/), [https://github.com/eclipse/mosquitto/commit/a3c680fbb00a0019573fb84c29332e845e6efcad](https://github.com/eclipse/mosquitto/commit/a3c680fbb00a0019573fb84c29332e845e6efcad), [https://security-tracker.debian.org/tracker/CVE-2023-0809](https://security-tracker.debian.org/tracker/CVE-2023-0809).