Description
In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21087 | In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker. |
Ubuntu USN |
USN-6492-1 | Mosquitto vulnerabilities |
References
| Link | Providers |
|---|---|
| https://bugs.eclipse.org/bugs/show_bug.cgi?id=573191 |
|
History
No history.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-04T00:12:50.247Z
Reserved: 2021-06-09T00:00:00.000Z
Link: CVE-2021-34431
No data.
Status : Modified
Published: 2021-07-22T14:15:08.050
Modified: 2024-11-21T06:10:23.867
Link: CVE-2021-34431
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN