Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-28366

Опубликовано: 01 сент. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

2.0.18-1
esm-apps-legacy/xenial

ignored

backporting risks regressions
esm-apps/bionic

ignored

backporting risks regressions
esm-apps/focal

ignored

backporting risks regressions
esm-apps/jammy

released

2.0.11-1ubuntu1.1
esm-apps/xenial

ignored

end of ESM support, was ignored [backporting risks regressions]
esm-infra-legacy/trusty

not-affected

code-not-present
focal

ignored

end of standard support, was ignored [backporting risks regressions]
jammy

released

2.0.11-1ubuntu1.1

Показывать по

EPSS

Процентиль: 69%
0.01321
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 3 лет назад

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

CVSS3: 7.5
nvd
около 3 лет назад

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

CVSS3: 7.5
debian
около 3 лет назад

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a ...

CVSS3: 7.5
github
около 3 лет назад

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

CVSS3: 7.5
fstec
около 3 лет назад

Уязвимость брокера сообщений Eclipse Mosquitto, связанная с ошибкой освобождения памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 69%
0.01321
Низкий

7.5 High

CVSS3