REDHAT-BUG-2318080: Use After Free
Published Oct 11, 2024
·Updated
In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.
Affected Software
1 affected component
Eclipse Mosquitto<2.0.18a
Event History
Oct 11, 2024
Data Sourced
via Red Hat·04:03 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2318080?
The severity of REDHAT-BUG-2318080 is critical due to the potential for memory leaks and segmentation faults.
2
How do I fix REDHAT-BUG-2318080?
To fix REDHAT-BUG-2318080, upgrade to Eclipse Mosquitto version 2.0.19 or newer.
3
What types of attacks are feasible with REDHAT-BUG-2318080?
Attacks such as memory leaking, segmentation faults, or heap-use-after-free can be executed by sending specific MQTT packets.
4
Which versions of Eclipse Mosquitto are affected by REDHAT-BUG-2318080?
Eclipse Mosquitto versions up to and including 2.0.18a are affected by REDHAT-BUG-2318080.
5
Who reported the REDHAT-BUG-2318080 vulnerability?
The REDHAT-BUG-2318080 vulnerability was reported by Red Hat.