First published: Fri Oct 11 2024(Updated: )
In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Messaging - Eclipse Mosquitto Distribution - Core | <2.0.18a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2318080 is critical due to the potential for memory leaks and segmentation faults.
To fix REDHAT-BUG-2318080, upgrade to Eclipse Mosquitto version 2.0.19 or newer.
Attacks such as memory leaking, segmentation faults, or heap-use-after-free can be executed by sending specific MQTT packets.
Eclipse Mosquitto versions up to and including 2.0.18a are affected by REDHAT-BUG-2318080.
The REDHAT-BUG-2318080 vulnerability was reported by Red Hat.