Описание
In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.
A flaw was found in Eclipse Mosquitto. A remote attacker may be able to trigger memory leakage, segmentation fault, or a heap-use-after-free condition by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE", and "PUBLISH" packets.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Satellite 6 | satellite-capsule:el8/mosquitto | Affected | ||
Red Hat Satellite 6 | satellite:el8/mosquitto | Affected | ||
Red Hat Satellite 6.14 for RHEL 8 | mosquitto | Fixed | RHSA-2024:8718 | 31.10.2024 |
Red Hat Satellite 6.14 for RHEL 8 | mosquitto | Fixed | RHSA-2024:8718 | 31.10.2024 |
Red Hat Satellite 6.15 for RHEL 8 | mosquitto | Fixed | RHSA-2024:8719 | 31.10.2024 |
Red Hat Satellite 6.15 for RHEL 8 | mosquitto | Fixed | RHSA-2024:8719 | 31.10.2024 |
Red Hat Satellite 6.16 for RHEL 8 | mosquitto | Fixed | RHSA-2024:8906 | 05.11.2024 |
Red Hat Satellite 6.16 for RHEL 8 | mosquitto | Fixed | RHSA-2024:8906 | 05.11.2024 |
Red Hat Satellite 6.16 for RHEL 9 | mosquitto | Fixed | RHSA-2024:8906 | 05.11.2024 |
Red Hat Satellite 6.16 for RHEL 9 | mosquitto | Fixed | RHSA-2024:8906 | 05.11.2024 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.
In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.
In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve me ...
In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.
EPSS
7.5 High
CVSS3