Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-897v-899r-j3hg

Опубликовано: 01 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

EPSS

Процентиль: 24%
0.00082
Низкий

7.5 High

CVSS3

Дефекты

CWE-401

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

CVSS3: 7.5
redhat
больше 2 лет назад

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

CVSS3: 7.5
nvd
больше 2 лет назад

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

CVSS3: 7.5
debian
больше 2 лет назад

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a ...

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость брокера сообщений Eclipse Mosquitto, связанная с ошибкой освобождения памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 24%
0.00082
Низкий

7.5 High

CVSS3

Дефекты

CWE-401