Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cm54-mprw-5279

Опубликовано: 30 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 7.2
CVSS3: 9.1

Описание

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.

EPSS

Процентиль: 44%
0.00213
Низкий

7.2 High

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-122
CWE-787

Связанные уязвимости

CVSS3: 9.8
ubuntu
8 месяцев назад

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.

CVSS3: 7.6
redhat
8 месяцев назад

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.

CVSS3: 9.8
nvd
8 месяцев назад

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.

CVSS3: 9.8
debian
8 месяцев назад

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a maliciou ...

CVSS3: 9.1
fstec
8 месяцев назад

Уязвимость брокера сообщений Eclipse Mosquitto, связанная с переполнением буфера в динамической памяти, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 44%
0.00213
Низкий

7.2 High

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-122
CWE-787