Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-8376

Опубликовано: 11 окт. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.

РелизСтатусПримечание
devel

not-affected

2.0.21-1
esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/xenial

needed

esm-infra-legacy/trusty

needed

focal

ignored

end of standard support, was needed
jammy

needed

noble

needed

Показывать по

EPSS

Процентиль: 55%
0.00321
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
9 месяцев назад

In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.

CVSS3: 7.5
nvd
9 месяцев назад

In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.

CVSS3: 7.5
debian
9 месяцев назад

In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve me ...

CVSS3: 8.3
redos
8 месяцев назад

Уязвимость mosquitto

CVSS3: 7.5
github
9 месяцев назад

In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.

EPSS

Процентиль: 55%
0.00321
Низкий

7.5 High

CVSS3

Уязвимость CVE-2024-8376