The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.
References
Configurations
History
No history.
Information
Published : 2023-09-01 16:15
Updated : 2024-01-07 10:15
NVD link : CVE-2023-28366
Mitre link : CVE-2023-28366
CVE.ORG link : CVE-2023-28366
JSON object : View
Products Affected
eclipse
- mosquitto
CWE
CWE-401
Missing Release of Memory after Effective Lifetime