« List of all CVEs

CVE-2024-8376

Memory leak

Published: 10/11/2024 Last updated: 10/31/2024 Reserved: 9/2/2024

In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.

CNA assigner: eclipse (e51fbebd-6053-4e49-959f-1b94eeb69a2c) Requested by: n/a

Metrics

Version Score Severity Vector String
4.0 7.2 High CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N

Opam packages affected (1)

conf-libmosquitto

Products affected (1)

Product Vendor Version
Mosquitto Eclipse Foundation n/a

References (8)

Credits (4)