Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-10525

Опубликовано: 30 окт. 2024
Источник: redhat
CVSS3: 7.6

Описание

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.

A flaw was found in Eclipse Mosquitto. If a malicious broker sends a specially crafted packet, it may trigger a buffer overflow condition in a client using libmosquitto. This issue can lead to an application crash or, in some circumstances, arbitrary code execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6mosquittoWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2322724mosquitto: heap buffer overflow in my_subscribe_callback

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
8 месяцев назад

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.

CVSS3: 9.8
nvd
8 месяцев назад

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.

CVSS3: 9.8
debian
8 месяцев назад

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a maliciou ...

CVSS3: 9.1
github
8 месяцев назад

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its on_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.

CVSS3: 9.1
fstec
8 месяцев назад

Уязвимость брокера сообщений Eclipse Mosquitto, связанная с переполнением буфера в динамической памяти, позволяющая нарушителю получить доступ к конфиденциальной информации

7.6 High

CVSS3