CVE-2023-3592: High severity tibco messaging - eclipse mosquitto distribution - core vulnerability
Published Oct 2, 2023
·Updated
In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.
Affected Software
2 affected componentsFixes available
debian/mosquitto<=2.0.11-1, <=2.0.11-1.2
1.5.7-1+deb10u12.0.11-1+deb11u12.0.11-1.2+deb12u12.0.18-1
Eclipse Mosquitto<2.0.16
Event History
Oct 2, 2023
CVE Published
via MITRE·07:01 PM
Data Sourced
via MITRE·07:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this memory leak in Mosquitto?
The vulnerability ID for this memory leak in Mosquitto is CVE-2023-3592.
2
What is the severity level of CVE-2023-3592?
The severity level of CVE-2023-3592 is medium with a score of 5.8.
3
How can the memory leak in Mosquitto be triggered?
The memory leak in Mosquitto can be triggered when clients send v5 CONNECT packets with a will message that contains invalid property types.
4
Which versions of Mosquitto are affected by CVE-2023-3592?
Versions up to and including 2.0.11-1.2 of Mosquitto are affected by CVE-2023-3592.
5
How can I fix the memory leak in Mosquitto?
To fix the memory leak in Mosquitto, update to version 2.0.16 or later.