Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-28366

Опубликовано: 01 сент. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

2.0.18-1
esm-apps/bionic

ignored

backporting risks regressions
esm-apps/focal

ignored

backporting risks regressions
esm-apps/jammy

released

2.0.11-1ubuntu1.1
esm-apps/xenial

ignored

backporting risks regressions
esm-infra-legacy/trusty

not-affected

code-not-present
focal

ignored

end of standard support, was ignored [backporting risks regressions]
jammy

released

2.0.11-1ubuntu1.1
lunar

released

2.0.11-1.2ubuntu0.1

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 2 лет назад

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

CVSS3: 7.5
nvd
больше 2 лет назад

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

CVSS3: 7.5
debian
больше 2 лет назад

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a ...

CVSS3: 7.5
github
больше 2 лет назад

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость брокера сообщений Eclipse Mosquitto, связанная с ошибкой освобождения памяти, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3