CVE-2024-3935: Eclipse Mosquito: Double free vulnerability
In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted PUBLISH packet to the broker a double free will occur with a subsequent crash of the broker.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3935?
CVE-2024-3935 is classified as a high severity vulnerability due to its potential impact on the security of the Mosquitto broker.
How do I fix CVE-2024-3935?
To mitigate CVE-2024-3935, upgrade to Eclipse Mosquitto version 2.0.19 or later, which includes a patch for this issue.
What versions of Eclipse Mosquitto are affected by CVE-2024-3935?
CVE-2024-3935 affects Eclipse Mosquitto versions from 2.0.0 to 2.0.18.
What kind of attack does CVE-2024-3935 facilitate?
CVE-2024-3935 could allow an attacker to exploit crafted PUBLISH packets to manipulate the broker's behavior in specific configurations.
Is CVE-2024-3935 related to network security?
Yes, CVE-2024-3935 impacts network security by potentially enabling unauthorized access or manipulation of broker activities.